{"id":364785,"date":"2026-09-14T11:04:13","date_gmt":"2026-09-14T11:04:13","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wwb-restaurant-menu-pro\/"},"modified":"2026-09-14T11:27:45","modified_gmt":"2026-09-14T11:27:45","slug":"wwb-restaurant-menu-pro","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/wwb-restaurant-menu-pro\/","author":23329786,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"3.4.5","stable_tag":"3.4.5","tested":"7.1","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"WWB Restaurant Menu Pro","header_author":"Aleksander Auset B\u00e6kkelund \u2013 WildWebBuilder","header_description":"Premium restaurant and caf\u00e9 menu system with food information engine, allergens, dietary tags, featured dishes, print\/PDF-friendly menu, drag & drop ordering and advanced design controls.","assets_banners_color":"504f48","last_updated":"2026-09-14 11:27:45","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":58,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","changelog"],"tags":{"3.4.5":{"tag":"3.4.5","author":"aleksa64","date":"2026-09-14 11:27:45","revision":3695082}},"upgrade_notice":{"3.4.5":"<p>Resolve request-method input validation warnings while preserving GET-only legacy admin redirects.<\/p>","3.4.4":"<p>Address nonce-review warnings and uninstall variable prefixing while preserving permanent PDF\/QR links and the admin access fixes.<\/p>","3.4.3":"<p>Fix admin access for hidden pages and old bookmarked menu URLs without changing role permissions or stored menu data.<\/p>","3.4.2":"<p>WordPress.org review cleanup with unique plugin prefixes and a one-time migration that preserves existing menu content and analytics history.<\/p>","3.4.1":"<p>WordPress.org review fixes for asset loading and request hardening; existing menu data and 3.4.0 privacy controls are preserved.<\/p>","3.4.0":"<p>GPL licensing, attribution, privacy controls and directory preparation.\nRe-enable analytics explicitly if wanted. Visitors must consent before collection.\nExisting menu data and analytics history remain unless you choose deletion.<\/p>","3.3.0":"<p>Admin refresh with settings preservation, import\/export and security fixes.\nReview external QR service consent after upgrading. Back up before installation.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3695012,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3695012,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3695012,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3695012,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["3.4.5"],"block_files":[],"assets_screenshots":{"screenshot-1.jpg":{"filename":"screenshot-1.jpg","revision":3695012,"resolution":"1","location":"assets","locale":"","width":1055,"height":1400}},"screenshots":[]},"plugin_section":[],"plugin_tags":[157429,232,12446,1865,20710],"plugin_category":[36,39,43],"plugin_contributors":[278709],"plugin_business_model":[],"class_list":["post-364785","plugin","type-plugin","status-publish","hentry","plugin_tags-allergens","plugin_tags-analytics","plugin_tags-food","plugin_tags-menu","plugin_tags-restaurant","plugin_category-analytics","plugin_category-business","plugin_category-customization","plugin_contributors-aleksa64","plugin_committers-aleksa64"],"banners":{"banner":"https:\/\/ps.w.org\/wwb-restaurant-menu-pro\/assets\/banner-772x250.jpg?rev=3695012","banner_2x":"https:\/\/ps.w.org\/wwb-restaurant-menu-pro\/assets\/banner-1544x500.jpg?rev=3695012","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/wwb-restaurant-menu-pro\/assets\/icon-128x128.png?rev=3695012","icon_2x":"https:\/\/ps.w.org\/wwb-restaurant-menu-pro\/assets\/icon-256x256.png?rev=3695012","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/wwb-restaurant-menu-pro\/assets\/screenshot-1.jpg?rev=3695012","caption":""}],"raw_content":"<!--section=description-->\n<p>Developed by Aleksander Auset B\u00e6kkelund \u2013 WildWebBuilder.com\nWordPress.org contributor: aleksa64.<\/p>\n\n<p>Manage your restaurant menu through a native WordPress administration workspace:\nOverview, Menu Items, Categories \/ Sections, Specials, Menu Order, Analytics,\nImport \/ Export \/ Demo, and Settings.<\/p>\n\n<p>Settings are organized into General, Appearance, Display, Food information,\nPrint \/ PDF, QR codes, Analytics, and Advanced. Saving one tab preserves the\nother tabs. Version 3.4.2 migrates legacy pre-review identifiers to the new <code>wwbrmp_<\/code> prefix while preserving menu posts, section relationships, settings, metadata, shortcode usage in WordPress content, and analytics history.<\/p>\n\n<p>Shortcodes:\n* [wwbrmp_restaurant_menu]\n* [wwbrmp_today_special]\n* [wwbrmp_featured_dishes limit=\"6\"]\n* [wwbrmp_menu_section category=\"Drinks\"]<\/p>\n\n<p>The PDF view is a printable HTML page for the browser's Print \/ Save as PDF\nfeature. It does not generate a binary PDF on the server.<\/p>\n\n<h3>Upgrade notes<\/h3>\n\n<p>The 3.3.0 release introduced an additive admin refactor, not a destructive migration.\nNo uninstall data removal is performed. Deactivation clears scheduled reports and retention cleanup.\nThe analytics schema is checked once per database version, including upgrades\nthat do not run the activation hook.<\/p>\n\n<p>Previous admin URLs for food information, PDF settings, QR codes and shortcodes\nremain available. Food\/PDF\/QR settings now appear inside Settings.<\/p>\n\n<p>Role behavior follows existing WordPress post capabilities: users with\nedit_posts can manage the items they are allowed to edit; categories and global\norder require manage_categories; settings, analytics and data tools require\nmanage_options. Sort requests also check edit_post for each submitted item.<\/p>\n\n<p>Order changes do not move items between categories. Edit section membership in\nthe native item editor. Items belonging to multiple sections use one shared\nmenu_order value; conflicting submitted positions are rejected.<\/p>\n\n<h3>Import and export<\/h3>\n\n<p>JSON format version 1 is supported, up to 5 MB and 1,000 menu items or sections.\nExports include item metadata, status, section hierarchy, media URLs and settings.\nThis is not a full site or database backup. Analytics history and image binaries\nare not exported. Analytics CSV contains at most 5,000 events for the period.<\/p>\n\n<p>Imports are validated before the preview is saved for 15 minutes. Applying an\nimport creates drafts and reuses sections by slug without changing existing\nsections. Repeated imports from the same source skip previously imported items.\nImages are linked only if their URL matches media already present locally;\nno remote media is downloaded. Settings are optional; analytics configuration,\nrecipients and external-service consent are never enabled by an import.<\/p>\n\n<p>Demo creates three drafts in a Demo Menu section and does not duplicate them\nwhen run again. Review food information and pricing before publishing samples.<\/p>\n\n<h3>External services<\/h3>\n\n<p>QR Server \/ goQR.me is an optional external QR image generator operated by\nFoundata GmbH. Endpoint: https:\/\/api.qrserver.com\/v1\/create-qr-code\/<\/p>\n\n<p>It is disabled until an administrator explicitly enables it in Settings &gt;\nQR codes, including after an upgrade. When enabled, QR previews\/downloads and\noptionally PDF covers request images from QR Server. Requests include the encoded\nmenu destination\/tracking URL, image size, foreground\/background colors and\noutput format. The requesting browser also contacts the service directly, so\nthe service receives normal connection information such as the browser IP.<\/p>\n\n<p>Service documentation: https:\/\/goqr.me\/api\/\nTerms of service: https:\/\/goqr.me\/legal\/tos-api.html\nPrivacy policy: https:\/\/goqr.me\/de\/rechtliches\/datenschutz-api.html\nLegal information: https:\/\/goqr.me\/legal\/<\/p>\n\n<p>No external analytics service is used. Report emails are sent through WordPress\nwp_mail to administrator-configured recipients and may use your site's mail\nprovider. Delivery depends on that provider and WP-Cron traffic. Scheduled times\nuse the WordPress site timezone.<\/p>\n\n<h3>Privacy and retention<\/h3>\n\n<p>Analytics is optional and off by default. Existing installations must explicitly\nactivate it again under Settings &gt; Analytics after upgrading to 3.4.0. Existing\nhistory is preserved. Enabling analytics shows visitors a choice on menu pages;\nevents are accepted only after visitor consent. A first-party preference cookie,\nwwbrmp_consent, remembers yes\/no for 180 days. The menu remains fully usable\nwithout analytics. The menu privacy control lets visitors withdraw consent.<\/p>\n\n<p>New analytics events contain menu item\/category, interaction type, source,\ntimestamp and viewing duration. Visitor hashes, persistent session identifiers,\npage URLs, referrers and user agents are no longer stored in event records.\nA keyed, one-minute IP-derived counter limits event requests; raw IPs are never\nwritten to that counter. New versions do not create the old localStorage visitor\nID; making a privacy choice removes any old wwbrmp_sid identifier.<\/p>\n\n<p>Historical records may still contain fields collected by older versions.\nSettings &gt; Analytics provides confirmed administrator actions to remove legacy\nvisitor information while preserving metrics, or delete history in batches of\n5,000 events. A configurable retention period of 30, 90 or 365 days can remove\nolder events daily, in batches of up to 5,000. The default keeps existing history\nuntil the administrator chooses otherwise. Cleanup depends on WP-Cron traffic.<\/p>\n\n<p>The plugin does not associate analytics records with emails or WordPress users,\nso it cannot reliably locate a visitor's historical events using WordPress's\nemail-based personal data tools. The administrator can instead remove legacy\nvisitor fields or event history using the documented privacy actions. Suggested\nprivacy policy text is added to WordPress's Privacy Policy Guide. This does not\nreplace the site owner's assessment of its privacy obligations.<\/p>\n\n<p>The unused legacy analytics_include_csv setting remains for compatibility;\nscheduled email attachments were not implemented in the original version.<\/p>\n\n<h3>License and attribution<\/h3>\n\n<p>Copyright (C) 2026 Aleksander Auset B\u00e6kkelund \u2013 WildWebBuilder.\nLicensed under the GNU General Public License, version 2 or any later version.\nSee LICENSE.txt for the license and COPYRIGHT.txt for attribution and dependencies.\nAuthor attribution appears in the plugin information and admin overview. No promotional footer is inserted into visitors' menus.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Back up your WordPress files and database before upgrading.<\/li>\n<li>Upload the ZIP in Plugins &gt; Add Plugin &gt; Upload Plugin. Replace the existing\nversion when prompted. The plugin folder remains wwb-restaurant-menu-pro.<\/li>\n<li>Activate the plugin if needed and open Restaurant Menu &gt; Overview.<\/li>\n<li>Review Settings &gt; QR codes before enabling the external QR service.<\/li>\n<\/ol>\n\n<!--section=changelog-->\n<h4>3.4.5<\/h4>\n\n<ul>\n<li>Validate, unslash, and sanitize the request method before checking legacy admin redirects.<\/li>\n<\/ul>\n\n<h4>3.4.4<\/h4>\n\n<ul>\n<li>Document narrowly scoped nonce-check exceptions for public read-only PDF views and HMAC-validated permanent QR links.<\/li>\n<li>Prefix the uninstall analytics-table variable with wwbrmp.<\/li>\n<li>Preserve the 3.4.3 admin access fixes and existing QR validation.<\/li>\n<\/ul>\n\n<h4>3.4.3<\/h4>\n\n<ul>\n<li>Restore hidden admin pages by retaining parent\/submenu registration through WordPress access checks.<\/li>\n<li>Redirect known pre-prefix admin URLs to registered wwbrmp pages with the original capability checks.<\/li>\n<li>Preserve the wwbrmp\/WWBRMP prefix migration and existing menu data.<\/li>\n<\/ul>\n\n<h4>3.4.2<\/h4>\n\n<ul>\n<li>WordPress.org review cleanup: unique <code>wwbrmp_<\/code> \/ <code>WWBRMP_<\/code> prefixes throughout plugin declarations and stored data.<\/li>\n<li>Added one-time migration for existing menu content, settings, metadata, analytics table and shortcode content.<\/li>\n<li>Removed Author URI from the plugin header to avoid review-time availability failures.<\/li>\n<li>Reviewed request handling, asset enqueueing, contributor metadata and privacy disclosures.<\/li>\n<\/ul>\n\n<h4>3.4.1<\/h4>\n\n<ul>\n<li>Address WordPress.org review feedback for script and style loading.<\/li>\n<li>Move printable PDF CSS and JavaScript to WordPress enqueue APIs.<\/li>\n<li>Harden long-lived QR redirects with signed URLs and configured-target validation.<\/li>\n<li>Add the correct WordPress.org contributor username.<\/li>\n<li>Preserve the 3.4.0 privacy, retention, translation and admin architecture changes.<\/li>\n<\/ul>\n\n<h4>3.4.0<\/h4>\n\n<ul>\n<li>Add GPLv2-or-later license and complete author\/contributor attribution.<\/li>\n<li>Require administrator activation and visitor opt-in for optional analytics.<\/li>\n<li>Minimize new event records and remove the persistent visitor identifier.<\/li>\n<li>Add optional retention, legacy-data removal and privacy policy guidance.<\/li>\n<li>Bound abuse counters and validate privacy actions with capability and nonce checks.<\/li>\n<li>Add cached analytics query helpers and document targeted static-check exceptions.<\/li>\n<li>Make settings schemas and additional admin\/frontend messages translatable;\ninclude a POT translation template.<\/li>\n<li>Restore return values for the admin parent\/submenu compatibility callbacks.<\/li>\n<li>Preserve existing menu posts, taxonomy IDs, metadata and shortcodes.<\/li>\n<\/ul>\n\n<h4>3.3.0<\/h4>\n\n<ul>\n<li>Consolidate administration into Restaurant Menu with a useful overview,\nnative content screens, specials, analytics, data tools and eight settings tabs.<\/li>\n<li>Split the single-file implementation into administration\/data-tool classes\nand compatibility-preserving settings, content, admin, analytics and frontend modules.<\/li>\n<li>Preserve unrelated settings server-side; remove duplicated forms, hidden\noption copies and the obsolete single-list sorting script.<\/li>\n<li>Add validated JSON preview\/import\/export and repeat-safe demo draft creation.<\/li>\n<li>Enforce per-item sort permissions, taxonomy membership and request validation;\nadd keyboard reorder controls, live status and serialized AJAX saves.<\/li>\n<li>Add analytics export nonces, CSV formula protection, bounded event fields,\nsafer SQL identifiers and versioned database setup.<\/li>\n<li>Correct report scheduling timezone, preserve report cursor and report mail failure.<\/li>\n<li>Add optional local-analytics collection control and explicit external QR consent.<\/li>\n<li>Load admin assets only on plugin screens; load sortable only on Menu Order.<\/li>\n<li>Preserve shortcodes, print layouts, database identifiers and old admin URLs;\nrepair visibility for imported items lacking the legacy hide metadata.<\/li>\n<li>Restore frontend filter script loading and move analytics JavaScript to an asset.<\/li>\n<li>Invalidate menu caches on save\/trash\/delete and prevent same-second collisions.<\/li>\n<\/ul>\n\n<h4>3.2.0<\/h4>\n\n<ul>\n<li>Supplied baseline: business-day analytics and scheduled reports.<\/li>\n<\/ul>","raw_excerpt":"Restaurant menus with dishes, sections, specials, print layouts, QR links and local analytics.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364785"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/aleksa64"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364785"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364785"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364785"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364785"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364785"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}