Claimlume Faucet Rewards

Description

Claimlume Faucet Rewards is a standalone rewards application using WordPress accounts and
administration without WooCommerce. New installations start with public reward,
registration, withdrawal, PTC and leaderboard features disabled.

Included: standalone landing and dashboard pages, account registration and email
verification, exact eight-decimal USD balances, transaction ledger, fixed/random
claims, daily streak bonuses, one-level referrals, timed PTC campaigns, manual
withdrawals, currencies with administrator-entered rates, notifications, badges,
XP, an optional pseudonymous leaderboard, image banner placements, editable public content,
WordPress email transport, CAPTCHA and privacy export/erasure callbacks.

External Services

Cloudflare Turnstile is optional and only contacted when the administrator
selects it. The browser loads its widget; the server sends the CAPTCHA token
and configured secret to Cloudflare for verification. Site hostname is checked.
Documentation: https://developers.cloudflare.com/turnstile/
Terms: https://www.cloudflare.com/website-terms/
Privacy: https://www.cloudflare.com/privacypolicy/

Administrator-configured logos and banners load from their entered image URLs.
The image host receives ordinary browser request data such as IP address and user
agent when the image is displayed. Banner destinations and sponsored visits open
administrator-entered external URLs only on user action. Those destination sites
receive ordinary browser request data and apply their own terms and privacy policy.
The plugin does not make server-side requests to sponsor URLs. Site operators must
use only sponsor programs that expressly permit incentivized or rewarded traffic.
Email uses the website’s existing WordPress mail transport. The plugin developer
does not operate telemetry, licensing, update, advertising or payment servers.

Google reCAPTCHA v2 checkbox is optional. When selected, the browser loads
Google’s widget and the server verifies the response token with the configured
secret. Tokens must pass the server response and hostname checks.
Documentation: https://developers.google.com/recaptcha/docs/verify
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy

hCaptcha is optional. When selected, the browser loads the hCaptcha widget and
the server sends the token, site key and secret to hCaptcha for verification.
Documentation: https://docs.hcaptcha.com/
Terms: https://www.hcaptcha.com/terms
Privacy: https://www.hcaptcha.com/privacy

FaucetPay and CWallet are optional manual payout destination types. The plugin
does not contact either service. If enabled, a member provides an account email,
username or ID; the site operator then uses that identifier outside WordPress to
send payment manually. Operators should disclose this processing in their privacy
policy and review the services’ current terms and privacy notices.
FaucetPay: https://faucetpay.io/
FaucetPay terms: https://faucetpay.io/legal/terms
FaucetPay privacy: https://faucetpay.io/legal/privacy
CWallet: https://cwallet.com/

Cloudflare, Google, hCaptcha, FaucetPay and CWallet are trademarks of their
respective owners. Claimlume Faucet Rewards is not affiliated with or endorsed by them.

Math verification binds to the member’s login session. For signed-out forms,
an essential HttpOnly browser cookie stores a random identifier for one day.
It does not contain an email, password or wallet address.

Updating from the original submission

Back up the database and plugin files. Deactivate the old Vdot Faucet plugin,
then install and activate Claimlume Faucet Rewards. Do not run both copies.
Do not delete the old copy through WordPress: its uninstaller can remove shared
permissions or data. Keep it deactivated until you have verified this replacement;
you can then remove the old plugin folder using your hosting file manager.
Existing balances, reward history, settings, page IDs, withdrawal records and
[vdot_faucet] shortcodes are reused. [claimlume_faucet] is also supported.
Legacy internal names are retained only for compatibility, not public branding.

Review validation

This revision passed PHP 8.1 and 8.5 syntax checks for all 22 PHP files,
JavaScript syntax checks, and isolated tests covering notice scope, default
branding migration, custom settings preservation, escaping, shortcode aliases
and exact amount calculations. These tests use WordPress function substitutes;
they are not a full WordPress/MySQL installation test or Plugin Check report.
Before public use, verify the member and administrator workflows on a staging
copy with your actual database, mail transport and selected CAPTCHA provider.

Screenshots

Installation

  1. Install on a WordPress 7.1+ single-site installation.
  2. Enable 64-bit PHP 8.1+ with OpenSSL, and a MySQL/MariaDB InnoDB database.
  3. Upload this ZIP through Plugins > Add New > Upload Plugin, then activate.
  4. Open Claimlume Faucet Rewards > Settings > Setup Wizard. Generated pages are drafts; review and publish only the pages you need.
  5. Verify email delivery. Choose and configure CAPTCHA under Settings > Security & CAPTCHA.
  6. Enter current currency rates before enabling manual withdrawals.
  7. Enable WordPress “Anyone can register” and the plugin registration setting only when the legal pages, email and abuse controls are ready.
  8. Test claims, PTC, referrals, rejection/refund and payout completion before handling funds.

No Composer, Node.js, Docker, WooCommerce or Laravel is needed at runtime. Generated pages use vf- prefixes to avoid overwriting existing website pages. You may choose Faucet Home as the homepage under Settings > Reading.

FAQ

Does this send cryptocurrency automatically?

No. Manual wallet, FaucetPay and CWallet are payout destination types, not API
integrations. Administrators send funds from their own wallet or service account,
then record the transaction reference. No payout API keys are stored.

Why are currencies initially disabled?

No live prices are invented. Enter a current USD price per coin and enable it.
Quotes expire after two minutes; rates expire after the configured age.

Why does the test account ask for verification?

Email verification is enabled by default. Use the email link. If wp_mail is not
configured, configure a WordPress SMTP plugin. An authorized administrator can
resend verification or review an account under Claimlume Faucet Rewards > Users.

Does this plugin protect against all bots?

No. Math CAPTCHA is for basic testing. Turnstile, rate limits and reward limits
help, but a public rewards service needs operational abuse monitoring.
The plugin does not replace security controls on the native wp-login.php route.

What happens when I delete the plugin?

Data is preserved by default. The explicit Tools setting enables permanent
removal of plugin data and generated pages. WordPress users are never deleted.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Claimlume Faucet Rewards” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.3

Review revision: new Siphorix branding and text domain, plugin-screen-only
notices, automatic directory translations and literal shared label translations.

Render initial balances and timers in the page. Guard frontend initialization
against older theme APIs and delayed DOM loading. Ignore dashboard responses
that predate successful claims. Preserve decimal strings during database writes
and restore missing wallets from their ledgers. Add dedicated CAPTCHA settings
saving, provider field switching and configuration shortcuts. Add opt-in payout
destinations, safer image-only advertising, draft setup pages, privacy disclosures,
member/admin workflow improvements and WordPress Plugin Check hardening.

1.0.2

Fixed claim balance persistence and recent-activity reliability by making member
notifications non-blocking, verifying wallet writes, and restoring missing wallet
rows. Added a protected Tools report and repair action for historical claims with
no matching ledger transaction. The faucet countdown now follows server time and
keeps claiming disabled until ready. Completed legacy CAPTCHA-key migration and
provider credential validation.

1.0.1

Fixed stale/IP-bound math challenges; added auto-refresh and reusable verification
controls. Added Google reCAPTCHA v2 and hCaptcha, per-provider secrets, setup
links and a live admin verification test. Grouped admin navigation into seven
sections. Added server-rendered PTC cards, campaign editing and visibility
reasons, shared listing logic and per-visit reward/duration snapshots. Fixed
JSON settings boolean imports and added table repair.

1.0.0

Initial rewards, PTC and manual withdrawal features.