=== ThemeMove Core ===
Contributors: thememove
Tags: core, thememove
Requires at least: 5.0
Tested up to: 6.7
Requires PHP: 7.4
Stable tag: 2.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Core functions for ThemeMove themes.

== Description ==

ThemeMove Core is a companion plugin for ThemeMove themes. It provides one-click demo import/export, mega menu, popup builder, customizer import/export, and other core utilities required by ThemeMove themes.

== Frequently Asked Questions ==

= Demo import stops mid-way with "Internal Server Error" (500) =

This usually means your web server killed the PHP process while the import was downloading media files. Apache with `mod_fastcgi` (e.g. MAMP PRO) has a 30-second idle timeout by default — long media downloads or large attachment batches can exceed it.

Enable **Strict FastCGI mode** by adding this line to your site's `wp-config.php` (above the `/* That's all, stop editing! */` line):

`define( 'TM_IMPORT_STRICT_FASTCGI', true );`

Or, equivalently, via a filter in a mu-plugin or your theme's `functions.php`:

`add_filter( 'tm_import_strict_fastcgi_mode', '__return_true' );`

Then re-run the demo import.

Strict mode does the following extra work during import:

* Blocks non-streaming HTTP requests (WooCommerce tracking, plugin update checks, etc.) that can hang for 30+ seconds
* Sends cURL keep-alive bytes during media downloads so the FastCGI idle timer keeps resetting
* Closes all nested output buffers on every flush so progress output actually reaches the browser
* Skips attachments whose URL points back to the current host but is missing locally (avoids a loopback FastCGI deadlock)
* Restricts thumbnail regeneration to newly-fetched image files only (prevents memory exhaustion on large media sets)
* Runs `wp_cache_flush()` + `gc_collect_cycles()` every 10 posts

Leave Strict mode **OFF** on standard hosting environments (mod_php, LiteSpeed/lsphp, nginx + PHP-FPM with normal timeouts) — the default importer behavior already works there. Only enable it if you actually hit a 500 / idle-timeout during demo import.

== Changelog ==

= 2.0.1 =
* Fix demo importer: PHP 8.x deprecations
* Fix demo importer: prevent FastCGI idle timeout 500

= 2.0.0 =
* Updated bundled CMB2 library to v2.11.0 (with class_exists guard to avoid conflict with standalone CMB2 plugin)
* Added gulp build tasks: translate (wp-pot), cmb2 update, zip package
* Security: added nonce verification (CSRF protection) to demo import forms
* Security: fixed XSS in breadcrumb output — all titles and URLs now properly escaped
* Security: fixed path traversal vulnerability in import/export file handling
* Security: fixed customizer import to use sanitize_text_field instead of esc_url_raw on tmp file path
* Import: auto-create nav_menu terms on-the-fly if missing from WXR, preventing "Menu item skipped" errors
* Import: register Essential Grid custom post type before WXR content import so category/tag terms are assigned correctly
* Import: automatically enable Essential Grid "Example Custom Post Type" option and flush rewrite rules during import
* Import: fixed WooCommerce attribute duplicate check using wp_list_pluck
* Import: fixed hello-world post status set to draft after import (was using invalid "unpublished" status)
* Import: fixed customizer import applying set_theme_mod correctly
* Export: added Revolution Slider export button (was hidden)
* Export: rewrote Revolution Slider export using $wpdb instead of system(mysqldump) for compatibility
* Export: Revolution Slider export now replaces site URL with %SITE_URI% placeholder and table prefix with wp_ for portability
* Fixed PHP 8.4 deprecation: implicit nullable parameter in Mobile_Detect constructor
* Fixed PHP deprecation: null key in array_key_exists (js_composer compatibility)

= 1.5.2 =
* Fixed security vulnerabilities
* Fixed WordPress Coding Standards (WPCS) issues across all files

= 1.5.1 =
* Fixed security vulnerabilities
* Updated language file (.pot)

= 1.4.2 =
* Fixed breadcrumb display issue

= 1.4.1 =
* Fixed deprecated WordPress functions
* Optimized code

= 1.3.8 =
* Initial release
