{"id":356029,"date":"2026-08-26T12:22:19","date_gmt":"2026-08-26T12:22:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/unbelievable-salon-booking\/"},"modified":"2026-08-26T12:21:45","modified_gmt":"2026-08-26T12:21:45","slug":"unbelievable-salon-booking","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/unbelievable-salon-booking\/","author":15647522,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.23.5","stable_tag":"3.23.5","tested":"7.1","requires":"5.8","requires_php":"8.2","requires_plugins":null,"header_name":"Unbelievable Salon Booking","header_author":"zgrkaralar","header_description":"Beautiful and easy to use salon booking plugin for WordPress","assets_banners_color":"","last_updated":"2026-08-26 12:21:45","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/unbelievable.digital","rating":0,"author_block_rating":0,"active_installs":0,"downloads":30,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"3.23.5":{"tag":"3.23.5","author":"zgrkaralar","date":"2026-08-26 12:21:45"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3666973,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3666973,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.23.5"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Frontend booking form \u2013 Clean and responsive design","2":"Admin dashboard \u2013 Overview of bookings and statistics","3":"Calendar view \u2013 Visual appointment management","4":"Service management \u2013 Create and organize services","5":"Staff management \u2013 Team members and schedules","6":"Working hours \u2013 Flexible schedule configuration","7":"Settings page \u2013 Customize plugin behavior"}},"plugin_section":[],"plugin_tags":[276,269,722,11523,4685],"plugin_category":[40],"plugin_contributors":[194569],"plugin_business_model":[],"class_list":["post-356029","plugin","type-plugin","status-publish","hentry","plugin_tags-appointment","plugin_tags-booking","plugin_tags-reservation","plugin_tags-salon","plugin_tags-scheduler","plugin_category-calendar-and-events","plugin_contributors-zgrkaralar","plugin_committers-zgrkaralar"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/unbelievable-salon-booking\/assets\/icon-128x128.png?rev=3666973","icon_2x":"https:\/\/ps.w.org\/unbelievable-salon-booking\/assets\/icon-256x256.png?rev=3666973","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Unbelievable Salon Booking is a comprehensive appointment management plugin designed for service-based businesses. Perfect for barbers, beauty salons, spas, wellness centers, consultants, and any business that needs to manage appointments efficiently.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li><strong>Service Management<\/strong> \u2013 Create unlimited services with custom duration and pricing<\/li>\n<li><strong>Category Organization<\/strong> \u2013 Group services into categories for better organization<\/li>\n<li><strong>Staff Management<\/strong> \u2013 Add team members with individual schedules and services<\/li>\n<li><strong>Working Hours<\/strong> \u2013 Set flexible working hours for each staff member<\/li>\n<li><strong>Breaks &amp; Holidays<\/strong> \u2013 Define lunch breaks and days off<\/li>\n<li><strong>Customer Database<\/strong> \u2013 Track customer history and contact information<\/li>\n<li><strong>Email Notifications<\/strong> \u2013 Automatic booking confirmations and reminders<\/li>\n<li><strong>SMS Notifications<\/strong> \u2013 Optional SMS alerts via NetGSM integration<\/li>\n<li><strong>Calendar View<\/strong> \u2013 Visual calendar for easy appointment management<\/li>\n<li><strong>Booking Form<\/strong> \u2013 Clean, responsive booking form via shortcode<\/li>\n<li><strong>Booking Management<\/strong> \u2013 Customers can view and cancel their bookings<\/li>\n<li><strong>Multi-language<\/strong> \u2013 Translation ready with 6 languages included<\/li>\n<\/ul>\n\n<h4>Included Languages<\/h4>\n\n<ul>\n<li>English<\/li>\n<li>Turkish (T\u00fcrk\u00e7e)<\/li>\n<li>German (Deutsch)<\/li>\n<li>French (Fran\u00e7ais)<\/li>\n<li>Russian (\u0420\u0443\u0441\u0441\u043a\u0438\u0439)<\/li>\n<li>Bulgarian (\u0411\u044a\u043b\u0433\u0430\u0440\u0441\u043a\u0438)<\/li>\n<\/ul>\n\n<h4>Shortcodes<\/h4>\n\n<ul>\n<li><code>[unbsb_booking_form]<\/code> \u2013 Display the booking form<\/li>\n<li><code>[unbsb_services]<\/code> \u2013 Show available services list<\/li>\n<li><code>[unbsb_staff_list]<\/code> \u2013 Display staff members<\/li>\n<li><code>[unbsb_manage_booking]<\/code> \u2013 Booking management page for customers<\/li>\n<\/ul>\n\n<h4>Perfect For<\/h4>\n\n<ul>\n<li>Barbershops<\/li>\n<li>Hair salons<\/li>\n<li>Beauty salons<\/li>\n<li>Spas &amp; wellness centers<\/li>\n<li>Massage therapists<\/li>\n<li>Nail salons<\/li>\n<li>Tattoo studios<\/li>\n<li>Consultants<\/li>\n<li>Any appointment-based business<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 5.8 or higher<\/li>\n<li>PHP 8.0 or higher<\/li>\n<li>MySQL 5.6 or higher<\/li>\n<\/ul>\n\n<h4>External Services<\/h4>\n\n<p>This plugin can connect to the external services listed below. <strong>None of these services are contacted unless the site administrator explicitly enables the related feature and provides their own credentials\/IDs.<\/strong> By default, all of them are disabled and no data leaves your site.<\/p>\n\n<p><strong>NetGSM SMS API<\/strong> (optional, off by default)\nUsed to deliver SMS notifications (booking confirmations, reminders, cancellations) when the administrator enables SMS notifications and enters their own NetGSM API credentials. Data sent: customer phone number and the SMS message content (booking details such as date, time, service name and staff name), at the moment a notification is triggered.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.netgsm.com.tr\/\">https:\/\/www.netgsm.com.tr\/<\/a> (API endpoint: <code>https:\/\/api.netgsm.com.tr\/<\/code>)<\/li>\n<li>Terms of Service: <a href=\"https:\/\/www.netgsm.com.tr\/sozlesme-ve-formlar\">https:\/\/www.netgsm.com.tr\/sozlesme-ve-formlar<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.netgsm.com.tr\/gizlilik-ve-guvenlik\/\">https:\/\/www.netgsm.com.tr\/gizlilik-ve-guvenlik\/<\/a><\/li>\n<\/ul>\n\n<p><strong>Google Sign-In (OAuth)<\/strong> (optional, off by default)\nUsed to let customers sign in with their Google account when the administrator enables social login and configures their own Google OAuth client. When a customer chooses \"Sign in with Google\", they are redirected to <code>accounts.google.com<\/code>; the site then exchanges the authorization code at <code>oauth2.googleapis.com<\/code> and retrieves the customer's name and email address from <code>www.googleapis.com<\/code> (or verifies a native app ID token via <code>oauth2.googleapis.com\/tokeninfo<\/code>). Data sent: the OAuth authorization code\/ID token issued by Google for that sign-in.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/developers.google.com\/identity\">https:\/\/developers.google.com\/identity<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/policies.google.com\/terms\">https:\/\/policies.google.com\/terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/policies.google.com\/privacy\">https:\/\/policies.google.com\/privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>Sign in with Apple<\/strong> (optional, off by default)\nUsed to let customers sign in with their Apple ID when the administrator enables it and configures their own Apple Services ID. Customers are redirected to <code>appleid.apple.com<\/code>; the plugin also fetches Apple's public signing keys from <code>appleid.apple.com\/auth\/keys<\/code> to cryptographically verify the returned identity token. Data sent: the identity token issued by Apple for that sign-in.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/developer.apple.com\/sign-in-with-apple\/\">https:\/\/developer.apple.com\/sign-in-with-apple\/<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/www.apple.com\/legal\/internet-services\/itunes\/\">https:\/\/www.apple.com\/legal\/internet-services\/itunes\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.apple.com\/legal\/privacy\/\">https:\/\/www.apple.com\/legal\/privacy\/<\/a><\/li>\n<\/ul>\n\n<p><strong>Google reCAPTCHA<\/strong> (optional, off by default)\nUsed to protect the public booking form against bots when the administrator enables it and enters their own reCAPTCHA keys. The reCAPTCHA script is loaded from <code>www.google.com<\/code> on pages containing the booking form, and each submitted form's CAPTCHA response is verified server-side against <code>www.google.com\/recaptcha\/api\/siteverify<\/code>. Data sent: the CAPTCHA response token and the visitor's IP address, on form submission.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.google.com\/recaptcha\/about\/\">https:\/\/www.google.com\/recaptcha\/about\/<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/policies.google.com\/terms\">https:\/\/policies.google.com\/terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/policies.google.com\/privacy\">https:\/\/policies.google.com\/privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>hCaptcha<\/strong> (optional, off by default)\nAlternative CAPTCHA provider, used the same way as reCAPTCHA when selected by the administrator. The hCaptcha script is loaded from <code>js.hcaptcha.com<\/code> and responses are verified against <code>hcaptcha.com\/siteverify<\/code>. Data sent: the CAPTCHA response token and the visitor's IP address, on form submission.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.hcaptcha.com\/\">https:\/\/www.hcaptcha.com\/<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/www.hcaptcha.com\/terms\">https:\/\/www.hcaptcha.com\/terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.hcaptcha.com\/privacy\">https:\/\/www.hcaptcha.com\/privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>Google Analytics 4<\/strong> (optional, off by default)\nUsed for visitor\/booking analytics when the administrator enables it and enters their own GA4 Measurement ID. The gtag.js script is loaded from <code>www.googletagmanager.com<\/code> on front-end pages and standard Google Analytics data (page views and booking funnel events) is sent to Google.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/marketingplatform.google.com\/about\/analytics\/\">https:\/\/marketingplatform.google.com\/about\/analytics\/<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/marketingplatform.google.com\/about\/analytics\/terms\/us\/\">https:\/\/marketingplatform.google.com\/about\/analytics\/terms\/us\/<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/policies.google.com\/privacy\">https:\/\/policies.google.com\/privacy<\/a><\/li>\n<\/ul>\n\n<p><strong>Meta (Facebook) Pixel &amp; Conversions API<\/strong> (optional, off by default)\nUsed for advertising analytics when the administrator enables it and enters their own Pixel ID (and, for the Conversions API, their own access token). The Pixel script is loaded from <code>connect.facebook.net<\/code> on front-end pages and events are sent to Facebook; when the Conversions API is enabled, booking events (event name, time, and hashed customer identifiers) are also sent server-side to <code>graph.facebook.com<\/code>.<\/p>\n\n<ul>\n<li>Service: <a href=\"https:\/\/www.facebook.com\/business\/tools\/meta-pixel\">https:\/\/www.facebook.com\/business\/tools\/meta-pixel<\/a><\/li>\n<li>Terms of Service: <a href=\"https:\/\/www.facebook.com\/legal\/terms\">https:\/\/www.facebook.com\/legal\/terms<\/a><\/li>\n<li>Privacy Policy: <a href=\"https:\/\/www.facebook.com\/privacy\/policy\/\">https:\/\/www.facebook.com\/privacy\/policy\/<\/a><\/li>\n<\/ul>\n\n<p><strong>\"Add to calendar\" links<\/strong>\nBooking confirmation pages\/emails can contain optional \"Add to Google Calendar \/ Outlook \/ Yahoo Calendar\" links. These are plain links that open the respective calendar service in the customer's browser with the appointment details pre-filled; the plugin itself sends no data to these services.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>unbelievable-salon-booking<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory<\/li>\n<li>Activate the plugin through the 'Plugins' menu in WordPress<\/li>\n<li>Go to 'Unbelievable Salon Booking' in the admin menu to configure the plugin<\/li>\n<li>Add your service categories and services<\/li>\n<li>Add your staff members and set their working hours<\/li>\n<li>Use the <code>[unbsb_booking_form]<\/code> shortcode to display the booking form on any page<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20display%20the%20booking%20form%3F\"><h3>How do I display the booking form?<\/h3><\/dt>\n<dd><p>Use the shortcode <code>[unbsb_booking_form]<\/code> on any page or post. You can also specify parameters like <code>[unbsb_booking_form service=\"1\" staff=\"2\"]<\/code>.<\/p><\/dd>\n<dt id=\"can%20i%20have%20multiple%20staff%20members%3F\"><h3>Can I have multiple staff members?<\/h3><\/dt>\n<dd><p>Yes, you can add unlimited staff members, each with their own schedule, services, and custom pricing.<\/p><\/dd>\n<dt id=\"does%20it%20support%20service%20categories%3F\"><h3>Does it support service categories?<\/h3><\/dt>\n<dd><p>Yes, you can organize your services into categories for better presentation.<\/p><\/dd>\n<dt id=\"can%20staff%20members%20have%20different%20prices%20for%20the%20same%20service%3F\"><h3>Can staff members have different prices for the same service?<\/h3><\/dt>\n<dd><p>Yes, each staff member can have custom pricing and duration for any service they offer.<\/p><\/dd>\n<dt id=\"is%20it%20mobile%20friendly%3F\"><h3>Is it mobile friendly?<\/h3><\/dt>\n<dd><p>Yes, the booking form is fully responsive and works perfectly on all devices including smartphones and tablets.<\/p><\/dd>\n<dt id=\"can%20i%20customize%20email%20notifications%3F\"><h3>Can I customize email notifications?<\/h3><\/dt>\n<dd><p>Yes, you can customize email templates for booking confirmations, reminders, and cancellations from the Settings page.<\/p><\/dd>\n<dt id=\"does%20it%20support%20sms%20notifications%3F\"><h3>Does it support SMS notifications?<\/h3><\/dt>\n<dd><p>Yes, SMS notifications are supported via NetGSM integration. More SMS providers will be added in future updates.<\/p><\/dd>\n<dt id=\"can%20customers%20manage%20their%20bookings%3F\"><h3>Can customers manage their bookings?<\/h3><\/dt>\n<dd><p>Yes, customers receive a unique link to view and cancel their bookings.<\/p><\/dd>\n<dt id=\"is%20it%20translation%20ready%3F\"><h3>Is it translation ready?<\/h3><\/dt>\n<dd><p>Yes, the plugin is fully translatable using standard WordPress translation methods. Turkish, English, German, French, Russian, and Bulgarian translations are included.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20any%20theme%3F\"><h3>Does it work with any theme?<\/h3><\/dt>\n<dd><p>Yes, Unbelievable Salon Booking is designed to work with any properly coded WordPress theme.<\/p><\/dd>\n<dt id=\"is%20there%20a%20pro%20version%3F\"><h3>Is there a Pro version?<\/h3><\/dt>\n<dd><p>A Pro version with additional features like payment integration, Google Calendar sync, and more SMS providers is planned for future release.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>3.23.5<\/h4>\n\n<ul>\n<li>Security: web Google\/Apple sign-in now requires a provider-verified email address before linking or creating an account (prevents account takeover via an unverified provider email).<\/li>\n<li>Security: the loyalty-progress REST endpoint now identifies the customer from the WordPress auth cookie and only ever returns the logged-in customer's own progress (no more lookups by arbitrary email).<\/li>\n<li>Security: the mobile-app promo validation endpoint is now per-IP throttled against code enumeration.<\/li>\n<li>Fix: rate-limiter transients can no longer be stored with a zero\/negative expiration.<\/li>\n<\/ul>\n\n<h4>3.23.4<\/h4>\n\n<ul>\n<li>Security: the web Sign in with Apple flow now cryptographically verifies the Apple ID token (RS256 signature against Apple's JWKS) before signing the user in \u2014 previously only iss\/aud\/exp claims were checked.<\/li>\n<li>Security: public loyalty-progress REST lookups are now IP rate-limited.<\/li>\n<li>Review feedback: every inline \/ is now delivered through wp_add_inline_script()\/wp_add_inline_style()\/wp_print_inline_script_tag(); JSON-LD output no longer uses JSON_UNESCAPED_SLASHES; transient keys are consistently unbsb_-prefixed; the placeholder image URL uses UNBSB_PLUGIN_URL instead of a hardcoded wp-content path.<\/li>\n<li>The \"Powered by\" credit under the booking form is now opt-in (Settings toggle, off by default).<\/li>\n<li>Updated bundled libraries: Chart.js 4.5.1, intl-tel-input 29.2.3 (bundled utils, webp flag sprites).<\/li>\n<li>readme: documented every external service (Google\/Apple sign-in, reCAPTCHA, hCaptcha, GA4, Meta Pixel\/CAPI, NetGSM) with data-flow details and working terms\/privacy links.<\/li>\n<li>Removed bundled .po\/.mo translation files (translate.wordpress.org handles translations) and the load_plugin_textdomain() call.<\/li>\n<\/ul>\n\n<h4>3.23.3<\/h4>\n\n<ul>\n<li>Security: public booking and promo-code AJAX endpoints are now IP rate-limited (5\/min for booking creation) \u2014 they are deliberately nonce-free for cache compatibility and previously relied on the honeypot\/CAPTCHA only.<\/li>\n<li>Hardening: remaining unsanitized\/unslashed inputs fixed, OAuth redirects use wp_safe_redirect with an allowed-hosts filter, debug logging gated behind WP_DEBUG.<\/li>\n<\/ul>\n\n<h4>3.23.2<\/h4>\n\n<ul>\n<li>WordPress.org readiness: removed the self-hosted update checker (WordPress.org is now the update channel), FullCalendar is bundled locally instead of loaded from a CDN, the optional GA4 loader is enqueued through the WordPress script API, and every Plugin Check error was resolved (SQL prepare, output escaping, translator comments).<\/li>\n<li>Fix: Customer View \"Wallet\" payment badge queried the wrong table name and never showed.<\/li>\n<\/ul>\n\n<h4>3.23.1<\/h4>\n\n<ul>\n<li>New: Conditional email-template blocks {if_cancel}, {if_reschedule}, {if_manage} \u2014 cancel\/reschedule wording is dropped automatically when the feature is disabled.<\/li>\n<\/ul>\n\n<h4>3.23.0<\/h4>\n\n<ul>\n<li>New: Soft delete for services, staff and categories with a \"Deleted items\" list and Restore.<\/li>\n<li>New: Edit Booking supports full multi-service editing (Bookings list + Calendar).<\/li>\n<li>Fix: Conflict check now runs against the new end time when a booking's services change.<\/li>\n<\/ul>\n\n<h4>3.22.x<\/h4>\n\n<ul>\n<li>New: Whole admin installable as a PWA (role-aware manifest, install prompt, offline page).<\/li>\n<li>Fix: Service Worker no longer cache-firsts third-party wp-admin assets.<\/li>\n<li>Fix: Mobile modal overflow, missing app-bar spacing, pinch-zoom on plugin screens, missing Card payment icon.<\/li>\n<\/ul>\n\n<h4>3.21.0<\/h4>\n\n<ul>\n<li>New: Mobile app shell (top bar, drawer, bottom tabs, bottom-sheet modals) on every plugin admin screen.<\/li>\n<\/ul>\n\n<h4>3.20.0<\/h4>\n\n<ul>\n<li>New: Reports page \u2014 P&amp;L over any date range with a month-by-month breakdown.<\/li>\n<\/ul>\n\n<h4>3.19.x<\/h4>\n\n<ul>\n<li>New: Inventory module \u2014 items, per-location stock, movement ledger, stock counts, staff order requests, low-stock alerts.<\/li>\n<li>New: Staff portal read-only colleague calendars; customer birthday list\/filters; dashboard Net Profit section.<\/li>\n<li>Fix: Staff could complete another staff member's booking via AJAX.<\/li>\n<\/ul>\n\n<p>Older releases: see changelog.txt in the plugin folder.<\/p>","raw_excerpt":"Professional appointment booking system for barbers, beauty salons, spas and service providers.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/356029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=356029"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/zgrkaralar"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=356029"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=356029"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=356029"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=356029"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=356029"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=356029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}