Maildroppa connects WordPress to your Maildroppa account. Place forms designed in Maildroppa, manage audience data and RSS newsletters from WordPress, and connect selected WordPress and Maildroppa events.
This plugin requires Maildroppa, a third-party email marketing service operated by Maildroppa. The following connections occur only for the described features.
https://api.maildroppa.com. Depending on the selected action, the request also contains resource IDs and subscriber email addresses, names, statuses, custom field values, tag assignments, field/tag/segment definitions, segment expressions, search/filter criteria, or pagination parameters. Maildroppa uses this data to authenticate the account and perform the requested email-marketing action.https://api.maildroppa.com/account. Maildroppa returns the stable account ID, account name and owner email shown in the admin header. WordPress stores a hash of that ID and the API origin to bind its cached forms and queued events to the account. Rotating a key within the same account preserves this binding. Switching to a different account is blocked while local forms, event settings, queued deliveries, or account webhooks still belong to the previous account./report/form with the selected date range and form IDs to show signup counts by form. The subscriber report uses /report/subscriber-status-total. Manually requesting double opt-in sends the entered subscriber data, the consent text and a consent source containing the WordPress administrator ID and UTC timestamp; Maildroppa may send a confirmation email.User-Agent header. This also applies to requests made by scheduled background tasks.https://api.maildroppa.com. Feed previews send the entered public feed URL. Creating or editing a newsletter sends its name, source/site/feed URLs and feed title, delivery schedule or threshold, selected segment, sender-profile and subscription-topic IDs, subject, email content, item limit, and approval policy. Status, feed-check, issue-history, release, cancellation, test-email, and archive actions send the selected newsletter and, where applicable, issue ID. Maildroppa uses this data to create and operate the requested RSS newsletter. Maildroppa servers fetch the configured public RSS feeds themselves.https://api.maildroppa.com/contact so Maildroppa can answer it. The “Include technical details” checkbox is selected by default and can be cleared before sending. When selected, the message also includes the plugin, WordPress and PHP versions, whether automatic WordPress cron is enabled, the last observed Maildroppa cron run, and API-key validation status. The administrator can inspect these details in the form. The automatically attached details contain no API key or subscriber data; the support request does not send the API key for authentication.https://api.maildroppa.com/events. Delivery runs in scheduled background requests, retries temporary failures a bounded number of times, and does not create a Maildroppa contact. Pending events expire 30 days after creation and will no longer be sent. Expired and permanently failed records, including the email address and selected properties, remain available for diagnosis for 30 days after failure; WordPress’s personal-data export and erasure tools include these records. Cleanup runs daily through WP-Cron while the plugin is active. Missed or disabled cron runs delay physical deletion; site operators must arrange regular WP-Cron execution. If an event cannot be queued, WordPress stores a diagnostic marker with event name, user ID, failure time, count and error message for at most 30 days, subject to daily WP-Cron cleanup. The queue has no fixed record-count limit. Maildroppa rejects events for people who are not Maildroppa subscribers and events without a matching automation; these are kept as failed records under the same retention.https://api.maildroppa.com/webhook-subscriptions. When the selected event occurs, Maildroppa sends a signed HTTPS request to that public receiver. The request contains the event ID and type, subscriber email and profile fields, tags, and event-specific form, confirmation, or tag details, together with timestamp, signature, event-ID, and delivery-ID headers. The plugin verifies the signature and acknowledges completed replays without running the event again during the 90-day retention period. Completed event IDs become eligible for deletion after 90 days for replay protection. Daily WP-Cron cleanup and incoming webhook requests remove expired records; missed cron runs can delay deletion. Disabling an event asks Maildroppa to stop sending it.MAILDROPPA_API_BASE_URL constant or environment variable, or the maildroppa_api_base_url WordPress filter. If changed, API requests, including authenticated requests with the API key and the Contact Form 7 requests described below, go to the configured URL instead of https://api.maildroppa.com.https://api.maildroppa.com/subscribers/wordpress-signup-requests to check whether the connected service supports this feature. The mapping, topic IDs and labels, consent text, and account/site binding are stored with the contact form in WordPress.https://api.maildroppa.com/subscribers/wordpress-signup-requests/{requestId}, authenticated with the API key. Maildroppa uses this data to process the signup through the account’s default signup flow and determine whether to send a double-opt-in confirmation email. Queuing a signup does not itself confirm a subscription. The visitor browser sends the contact form to WordPress; it does not send this signup directly to the Maildroppa API or load the hosted Maildroppa form runtime for this checkbox.https://form.maildroppa.com/md-form-loader.js and form styles from https://form.maildroppa.com. The browser requests these resources when it renders the page containing the form. The script then requests the selected form definition from https://api.maildroppa.com/form/{formId} using the form ID and a SHA-256 fingerprint (requires Web Crypto, normally available over HTTPS) derived from screen size, browser name and major version, and operating-system name and version. This loads and renders the selected hosted form and counts unique form views. The loader stores lastSeen{formId} in localStorage, loads images from https://static.maildroppa.com, and may load videos from YouTube, Vimeo or another URL configured in the form. Those providers receive the IP address and browser request headers when their resources load.https://api.maildroppa.com/form/{formId} using the same fingerprint. Native forms use a shorter non-cryptographic fingerprint if Web Crypto is unavailable or fails. This keeps required fields and consent aligned with Maildroppa and counts unique form views while the WordPress theme controls presentation.https://api.maildroppa.com/subscribe. Normal HTTPS request data, including the visitor IP address, user agent, and any referrer information the browser permits, also reaches Maildroppa. Maildroppa uses this data to process the requested newsletter signup, topic choices, and related consent workflow.https://form.maildroppa.com and connections to https://api.maildroppa.com for these forms, plus images from https://static.maildroppa.com and any configured video providers.MAILDROPPA_PUBLIC_FORM_BASE_URL constant or environment variable, or the maildroppa_public_form_base_url WordPress filter. The maildroppa_public_form_loader_url filter can override the hosted loader script URL independently. If changed, hosted form scripts and styles load from the configured URL. Native form definitions and submissions use the API base URL. The hosted loader uses its own configured API origin.https://form.maildroppa.com/md-form-preview.js and styles from https://form.maildroppa.com/index.css into the administrator’s browser. This also happens when the form has not been placed on a public page. The preview requires administrator access and a valid WordPress nonce. WordPress requests the selected form’s preview data from the Maildroppa API using the API key and form ID, and supplies that data to the preview renderer. Native-form previews use the plugin’s local renderer and WordPress REST endpoints. Preview submissions are intercepted locally and do not send newsletter signups or confirmation emails. Resource requests still send normal browser request data, including IP address and user agent, to the resource host. A configured public form base URL also changes the hosted preview script and style origin.https://app.maildroppa.com or https://maildroppa.com only after an administrator clicks them. Resource links include the selected subscriber, campaign, form or newsletter ID; other links send only normal browser request data.Maildroppa privacy notice: https://maildroppa.com/data-protection
Maildroppa terms of service: https://maildroppa.com/terms
The optional debug setting in maildroppa_options logs failed API requests only when WordPress debug logging is enabled. It records method, redacted route, status and error ID; API keys, message bodies and subscriber email addresses are excluded. Keep debug logging disabled unless investigating a problem, restrict access to the log and delete it after diagnosis.
All PHP, JavaScript and CSS files are unminified source files; no build step is required. The bundled .mo and .json translation files are built from translation sources maintained in the development repository.