FonX Delete User turns account erasure into a controlled, reviewed process instead of a one-click auto-delete.
Most “delete my account” plugins force visitors into their own button or form. FonX Delete User takes the opposite approach: you keep the form you already have and the plugin quietly powers it in whichever way fits your site.
This release addresses the points raised during the plugin review and hardens two runtime paths found while testing. Details of what changed and why:
fxldu prefix instead of the generic du_ / delete_user_ names: option keys, database tables, transients, the REST namespace (fxldu/v1), action/filter names, nonces, admin menu slugs, the [fxldu_form] shortcode, the fxldu/form block, enqueue handles, JavaScript globals, and frontend CSS classes. PHP constants are FXLDU_* and the class namespace is Fxldu\. The text domain fonx-delete-user and the plugin folder name are unchanged.$wpdb->prepare() when no filter or search is applied; in that case the static count query runs directly instead of emitting the “the query argument must have a placeholder” notice.<form> itself), field collection and email resolution now read the named inputs directly instead of throwing inside new FormData(). The window integration-guard is __fxlduIntegrationBound.<script> tags. The shortcode and block register the fxldu-frontend script through wp_enqueue_script() and inject the config object with wp_add_inline_script( 'fxldu-frontend', $js, 'before' ). The unused print_frontend_config() method was removed from the main plugin file, and no <script> or <style> strings remain in the plugin source.sanitize_textarea_field( wp_unslash( $_POST['api_headers'] ) ) before building the request, matching the sanitization applied when the headers are saved.Contributors: header now uses the plugin owner’s WordPress.org username.WP_CONTENT_DIR path. Logs now go to a plugin-specific subfolder under the uploads directory ({uploads}/fxldu/fxldu-logs.log), created with wp_mkdir_p(), and each line is appended with error_log( $line, 3, $log_path )./external-request route remains open for anonymous form submissions but is now hardened: it keeps the honeypot check and the per-site token verification, strips internal keys from the forwarded payload, fails closed with HTTP 403 unless External API mode is active, and is rate-limited per IP (its own transient counter so a normal submission still counts only once per endpoint leg).option_name LIKE query (which could delete options owned by other plugins sharing the old prefix) and a usermeta LIKE cleanup (the plugin writes no user meta) were removed. uninstall.php now deletes an explicit list of the 26 options owned by this plugin plus the three plugin-owned database tables.fxldu_rate_limit filter documented in the FAQ is now actually applied. Both the /request and /external-request endpoints enforce their per-IP limit through a shared helper whose default is max( 1, Options::get_rate_limit() ) and which honors apply_filters( 'fxldu_rate_limit', $limit, $ip ).