Description
Lead to Cash by NimblePlugins is a self-hosted workflow for service businesses that want to manage the path from enquiry to invoice inside WordPress.
The Free plugin includes:
- Enquiries and manual lead creation
- Customers
- Quotes and PDF documents
- Jobs and completed work
- Invoices and payment tracking
- Standard reports and an audit log
- In-app notifications
- Search and export tools
- Local encryption of sensitive fields
- WordPress personal-data export and erasure integration
- English as the default product language
- Danish language and economic defaults
- A searchable Help & FAQ centre in English and Danish
- Lead to Cash user administration in WordPress
- Scheduled backups of Lead to Cash data, kept on the server, with restore and import of a saved backup file
Lead to Cash contains no licence check, no account requirement and no time limit. A product key applies only to the separately installed Lead to Cash Pro add-on, whose code is not part of this plugin.
Your operational data is stored in dedicated tables in your WordPress database, and backups are kept there too. It leaves the server only when you ask it to: see External services.
Product information: https://nimbleplugins.com/lead-to-cash/
External services
Lead to Cash runs on your own server and never contacts NimblePlugins. It contacts the services below, and only for the feature named.
Danish company register, CVR (only when a user looks up a CVR number)
When a user enters a Danish CVR number on a customer card and asks for the details, the eight-digit number is sent to cvrapi.dk to fetch the registered company name and address. The request also carries this site’s host name in the User-Agent header, because cvrapi.dk rejects anonymous calls. Nothing else is sent, and no customer data leaves the site. An answer is cached for twelve hours, so looking the same number up again does not call out again.
Service: https://cvrapi.dk/ – Terms: https://cvrapi.dk/terms – What data they hold and why: https://cvrapi.dk/help
VAT-number lookup (only when a user clicks it)
When a user looks up a customer’s VAT number, the country code and the number are sent to the European Commission’s VIES service (ec.europa.eu) to fetch the registered company name and address. Nothing else is sent. Service: https://ec.europa.eu/taxation_customs/vies/ – Legal notice: https://commission.europa.eu/legal-notice_en – Privacy: https://commission.europa.eu/privacy-policy-websites-managed-european-commission_en
Logo and payment QR image
If the company logo or payment QR code is given as a web address, Lead to Cash downloads that image to place it in PDF documents. Only the address you enter is requested, and nothing about your data is sent. Normally this is an image in your own media library.
Backup destinations (only with the separate Pro add-on)
Lead to Cash takes backups and keeps them on this server. Sending a copy somewhere else is what Pro adds: Pro registers the destinations, and without Pro there are none, so a backup stays where it was made.
This package does contain the Dropbox client class, because Pro builds on it rather than carrying its own copy. It is never reached without Pro: every path to it runs through a destination, and no destination exists until Pro registers one.
With Pro installed and a destination configured, the backup archive is uploaded to the destination you chose, each time a backup runs. The archive contains all Lead to Cash data, so choose a destination you would trust with the database itself.
Dropbox: https://www.dropbox.com/ – Terms: https://www.dropbox.com/terms – Privacy: https://www.dropbox.com/privacy
Google Drive: https://www.google.com/drive/ – Terms: https://policies.google.com/terms – Privacy: https://policies.google.com/privacy
OneDrive and SharePoint: https://www.microsoft.com/microsoft-365/onedrive – Terms: https://www.microsoft.com/servicesagreement – Privacy: https://www.microsoft.com/en-us/privacy/privacystatement
SFTP and webhook destinations go to an address you enter yourself; no third party is involved beyond the one you choose.
Source code
Lead to Cash has no build step. The JavaScript and CSS shipped in frontend/ and admin/ are the source: written by hand, not generated, bundled or minified, and they are the same files the browser loads. There is nothing to un-minify, and there are no build tools to document.
Privacy
Lead to Cash stores contact details, enquiry details, notes, document data and activity history in the local WordPress database. Sensitive fields are encrypted locally.
The plugin integrates with WordPress personal-data export and erasure tools. Site administrators remain responsible for defining suitable retention periods. Financial records may need to be retained under applicable bookkeeping rules.
Lead to Cash does not contact NimblePlugins. Backups sent to a destination contain all Lead to Cash data; choose a destination you would trust with the database itself.
Screenshots
















Installation
- Install the ZIP through Plugins > Add New > Upload Plugin, or upload the
nimble-lead-to-cashfolder to/wp-content/plugins/. - Activate Lead to Cash by NimblePlugins.
- Open Lead to Cash in the WordPress admin menu.
- Configure language and company settings.
- Open the private Lead to Cash app from the admin menu.
FAQ
-
Is Pro required?
-
No. The workflow for enquiries, customers, quotes, jobs, invoices, reports and exports is complete on its own.
-
Where is customer data stored?
-
In dedicated tables in the site’s WordPress database. Sensitive contact and activity fields are encrypted with a local installation key.
-
Does the Free plugin send telemetry?
-
No. Lead to Cash sends no analytics or telemetry.
-
Where is the encryption key stored?
-
Sensitive fields are encrypted locally with a key that is never sent anywhere. The key is read from the constant NIMBLE_LTC_ENCRYPTION_KEY_B64 in wp-config.php if you define one, and otherwise from an option in the database.
Defining it in wp-config.php is recommended. It keeps the key out of the database, so a database copy on its own — a support export, a shared dump, or a vulnerability in another plugin — cannot decrypt your customer data. Lead to Cash > Overview shows the exact line to add and can remove the database copy once it is in place.
-
Does the plugin contact an external service?
-
Only when you use a feature that needs one: the VAT-number lookup, or a logo or QR image you point at by web address. Nothing is sent to NimblePlugins, and nothing is sent at all until a user asks for it. Backups stay on this server. See External services for the details.
-
What happens if I deactivate the plugin?
-
Data is preserved. Deactivation does not remove customer or pipeline data.
-
Can I delete all plugin data on uninstall?
-
Yes. This is opt-in under Lead to Cash settings. If enabled before uninstalling Free, plugin-owned database tables, settings, private storage, local backups and the encryption key are removed. Leave the option disabled to preserve records.
-
Can I export or erase personal data?
-
Yes. The plugin integrates with WordPress Tools > Export Personal Data and Erase Personal Data.
-
What changes when Danish is selected?
-
New documents use Danish defaults such as DKK, 25% VAT, CVR labels and Danish document prefixes. Existing saved documents keep their historical values.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Nimble Lead to Cash” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Nimble Lead to Cash” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
The full history from 1.0.0 onwards is in changelog.txt, which ships with
the plugin.
1.37.8
- Signing in lasts. The session had a flat eight-hour life from the moment of signing in and was never extended – so a working day that began at eight ended with being signed out at four, mid-task, with a two-factor code to find. It now slides: an authenticated request pushes the expiry forward, throttled to the same five-minute write that already recorded activity, and a session in regular use stays valid. Fourteen days without use ends it, and a ceiling of ninety days from the sign-in applies however much it is used, so a session cannot live indefinitely.
- A device can be remembered, so the two-factor code is not demanded on every sign-in. The choice appears beside the code field, and only when Nimble Security is installed and the site has turned remembered devices on. The password is still required on a remembered device – only the code is skipped – and the device can be removed again from Nimble Security at any time.
1.37.7
- The enquiry, customer and job screens are usable on a phone again. Their two columns never stacked: the activity sidebar held its 280px floor while the form column gave up everything, leaving it 114px wide on a 412px screen, with every field clipped to a few letters. The stacking rule existed, but a media query carries no specificity, so the general rule lost to the narrower one these dialogs brought with them. It is now stated at that scope. Measured at 412, 390 and 360px; the desktop layout is unchanged to the pixel.
- Settings, documents had the same fault one screen over – the side panel’s second column came out ten pixels wide on a phone. Fixed in the same place.
- The frontend now reads its translations from WordPress. Its JavaScript asked for a text domain the plugin does not declare, and script translations were never registered, so every translation of the 486 frontend strings was decorative. The domain is aligned and the script registered, which means an approved translation on translate.wordpress.org now arrives without a release.
- 137 strings that the bundled dictionary did not cover appeared in English inside a translated interface. They are filled in, and the build now refuses to package a frontend where that is true again.
1.37.6
- A status you choose now survives an update. A one-off repair that aligned every enquiry with its newest action sat in the schema installer, which runs on every activation and every schema change – so each update quietly rolled back any status a person had set since, with nothing written to the timeline to say it had happened. It now runs once: an installation that already has a schema version is marked as done rather than repaired again, and only a fresh install, which has no enquiries to touch, reaches the query at all.
- The same repair left only Won and Lost alone, while the two live rules also protect Quote sent. A sent quote could therefore be rolled back to “Meeting” by an update. The three are now treated the same in all three places.
- An invoice notification arrives on the due date, not three days early. The query asked for everything due within three days; it now asks for what is due. Quotes keep their three days’ notice – a quote expires by itself and there is something to do before it does, while an invoice needs nothing until it is actually due.
1.37.5
- The readme now documents every external service the plugin can reach, with
what is sent, when, and links to each service’s terms and privacy policy. - Corrected the readme and a code comment that said the code for off-site
backup destinations ships with the Pro add-on. The Dropbox client class
ships here; Pro builds on it. Without Pro it is never reached. - The Danish translation files are no longer bundled. Translations now come
from translate.wordpress.org, which keeps them current without a release.
1.37.4
- The report CSV export was written in Danish throughout, even when the app was
set to English, so an English user got a Danish file from an English screen.
Every row label is now translated; the Danish wording is unchanged. - Two dashboard tiles counted invoices with the Danish word “fakturaer” in the
English interface. They now say “invoice” or “invoices”.
1.37.3
- Two labels were written in Danish directly in the template, so they stayed
Danish whatever language the app was set to: the “Create credit note” button
on an invoice, and the default quote introduction field in settings. Both are
English now, with the Danish kept in the translation dictionary, so a Danish
user sees no change.
1.37.2
- The Easy Setup screen drew its mark as the letter N in a coloured box rather
than using the plugin’s own icon. It now shows the icon itself.
1.37.1
- The app icon was the family’s blue, which belongs to Nimble Security. Lead to
Cash is indigo. The icon in the browser tab, on the sign-in screen, in the
sidebar and on the installed app now matches the plugin’s own colour, and so
does the mark on the Easy Setup screen, which had the old blue written into
the stylesheet rather than taking it from the icon.
1.37.0
- The enquiry, customer and job screens are now laid out the same way. Activity
sits in a column on the right in all three, so nothing moves when an enquiry
becomes a customer, and the save bar stays at the foot of the window however
long the record is. - The same screens are considerably shorter. Fields are tighter, a postcode,
city and country share one line, and a billing address that matches the work
address is a single line instead of a repeated form. A customer record that
needed 2,944 pixels of scrolling now needs 1,645. - Every section is a card with its own heading, so the seams between contact
details, actions, documents, invoices and activity are visible at a glance. - Documents on an enquiry were nested inside the actions panel and looked like
part of it. It is its own section now.
1.36.3
- Renamed TermsAttachment::prepare() to attachment(). Plugin Check treats every
call named prepare() as $wpdb->prepare() and reads its first parameter, which
a method without parameters does not have; the check crashed on the file
rather than reporting anything about it. Behaviour is unchanged.
1.36.2
- Five repository files were missing the note that explains their access-scope
clauses, so the report still listed them. No code changed.
