{"id":245535,"date":"2025-08-13T13:22:32","date_gmt":"2025-08-13T13:22:32","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ko-fi-members\/"},"modified":"2026-09-20T07:11:13","modified_gmt":"2026-09-20T07:11:13","slug":"members-for-kofi","status":"publish","type":"plugin","link":"https:\/\/nl.wordpress.org\/plugins\/members-for-kofi\/","author":13969194,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.1","requires":"5.6","requires_php":"7.4","requires_plugins":null,"header_name":"Members for Ko-fi","header_author":"Sune Adelowo Trudslev","header_description":"Integrate with Ko-fi to manage WordPress users or roles via webhook.","assets_banners_color":"376699","last_updated":"2026-09-20 07:11:13","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/ko-fi.com\/foodgeek","header_plugin_uri":"https:\/\/github.com\/trudslev\/members-for-kofi","header_author_uri":"https:\/\/foodgeek.io","rating":0,"author_block_rating":0,"active_installs":10,"downloads":559,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"trudslev","date":"2025-08-13 13:24:58","revision":3344091},"1.0.1":{"tag":"1.0.1","author":"trudslev","date":"2025-09-06 11:34:20","revision":3357078},"1.1.0":{"tag":"1.1.0","author":"trudslev","date":"2026-09-20 07:11:13","revision":3703946}},"upgrade_notice":{"1.1.0":"<p>New features: automatic log cleanup, a request log viewer and a reorganized settings page. Also includes security hardening and several fixes. Your existing settings are kept.<\/p>","1.0.1":"<p>Maintenance release: improved packaging only. No action required.<\/p>","1.0.0":"<p>Initial release. No upgrade steps required.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3344091,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3344091,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3344091,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3344091,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3703946,"resolution":"1","location":"assets","locale":"","width":1890,"height":2500},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3703946,"resolution":"2","location":"assets","locale":"","width":1902,"height":1362}},"screenshots":{"1":"<strong>Settings<\/strong>: the Ko-fi connection, role assignment and log retention on a single page. Your webhook URL is shown ready to copy into Ko-fi, and the verification token is masked.","2":"<strong>Logs<\/strong>: user activity with the action taken for each donation. The Log Type selector switches to the webhook request log, and the list can be searched, paged and cleared."}},"plugin_section":[],"plugin_tags":[246270,1932,1915,2461,15439],"plugin_category":[58],"plugin_contributors":[246271],"plugin_business_model":[],"class_list":["post-245535","plugin","type-plugin","status-publish","hentry","plugin_tags-ko-fi","plugin_tags-membership","plugin_tags-roles","plugin_tags-user-management","plugin_tags-webhook","plugin_category-user-management","plugin_contributors-trudslev","plugin_committers-trudslev"],"banners":{"banner":"https:\/\/ps.w.org\/members-for-kofi\/assets\/banner-772x250.png?rev=3344091","banner_2x":"https:\/\/ps.w.org\/members-for-kofi\/assets\/banner-1544x500.png?rev=3344091","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/members-for-kofi\/assets\/icon-128x128.png?rev=3344091","icon_2x":"https:\/\/ps.w.org\/members-for-kofi\/assets\/icon-256x256.png?rev=3344091","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/members-for-kofi\/assets\/screenshot-1.png?rev=3703946","caption":"<strong>Settings<\/strong>: the Ko-fi connection, role assignment and log retention on a single page. Your webhook URL is shown ready to copy into Ko-fi, and the verification token is masked."},{"src":"https:\/\/ps.w.org\/members-for-kofi\/assets\/screenshot-2.png?rev=3703946","caption":"<strong>Logs<\/strong>: user activity with the action taken for each donation. The Log Type selector switches to the webhook request log, and the list can be searched, paged and cleared."}],"raw_content":"<!--section=description-->\n<p>Members for Ko-fi is a WordPress plugin that integrates with Ko-fi to manage WordPress users and roles based on Ko-fi webhooks. This plugin allows you to automate user role assignments, log donations (in a database table), and manage memberships seamlessly.<\/p>\n\n<p><strong>Features:<\/strong>\n- Automatically assign roles to users based on Ko-fi donations or memberships.\n- Log user actions, such as donations and role changes, in a dedicated database table (no file logging).\n- Lightweight debug logging to the PHP error log when WP_DEBUG is enabled.\n- Stores only what it needs, and removes it all when you uninstall.<\/p>\n\n<p><strong>Use Cases:<\/strong>\n- Reward your Ko-fi supporters with exclusive access to content or features.\n- Automate user role management for subscription-based memberships.\n- Track and log user activity for better insights.<\/p>\n\n<h3>License<\/h3>\n\n<p>This plugin is licensed under the GPLv3 or later. See the <a href=\"https:\/\/www.gnu.org\/licenses\/gpl-3.0.html\">GNU General Public License<\/a> for more details.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/members-for-kofi<\/code> directory, or install the plugin through the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Configure the plugin under <strong>Members for Ko-fi<\/strong> in the main admin menu (it has its own entry, with a heart icon).<\/li>\n<li>Set up your Ko-fi webhook to point to your WordPress site.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20set%20up%20the%20ko-fi%20webhook%3F\"><h3>How do I set up the Ko-fi webhook?<\/h3><\/dt>\n<dd><ol>\n<li>Log in to your Ko-fi account and open the webhooks page: https:\/\/ko-fi.com\/manage\/webhooks<\/li>\n<li>Set the webhook URL to your site followed by <code>\/webhook-kofi<\/code>, for example <code>https:\/\/your-site.com\/webhook-kofi<\/code>.<\/li>\n<li>Copy the Verification Token (under Advanced) into <strong>Members for Ko-fi &gt; Settings<\/strong> in WordPress.<\/li>\n<\/ol><\/dd>\n<dt id=\"how%20do%20i%20test%20my%20setup%20without%20waiting%20for%20a%20real%20payment%3F\"><h3>How do I test my setup without waiting for a real payment?<\/h3><\/dt>\n<dd><p>Ko-fi's webhook page has test buttons that send a real request to your site. Use them, then open <strong>Members for Ko-fi &gt; Logs<\/strong> and check both the Request log and the User log.<\/p>\n\n<p>The buttons all use the same fake supporter, <strong>Jo Example<\/strong> (<code>jo.example@example.com<\/code>), so a successful test creates a real WordPress user with that address. Delete it when you are done.<\/p>\n\n<p>What each button sends:<\/p>\n\n<ul>\n<li><strong>Send single tip test<\/strong> - a one-off tip of 3.00 USD, with no tier.<\/li>\n<li><strong>Send first monthly test<\/strong> - a first subscription payment of 3.00 USD, with no tier.<\/li>\n<li><strong>Send membership tier test<\/strong> - a renewal subscription payment of 5.00 USD for the tier named <strong>Bronze<\/strong>.<\/li>\n<\/ul><\/dd>\n<dt id=\"i%20ran%20a%20test%20and%20nothing%20happened.%20why%3F\"><h3>I ran a test and nothing happened. Why?<\/h3><\/dt>\n<dd><p>Three settings decide whether a test does anything, and all three are working as intended when a test appears to be ignored:<\/p>\n\n<ul>\n<li><strong>\"Only process subscription payments\" is enabled.<\/strong> The <em>single tip<\/em> test is not a subscription payment, so it is ignored on purpose. Use the <em>first monthly<\/em> or <em>membership tier<\/em> test instead. The Request log will still show the request arriving with a 200, and the User log will say \"Ignored non-subscription payment\".<\/li>\n<li><strong>You use tier mappings but have no matching tier.<\/strong> Only the <em>membership tier<\/em> test sends a tier name, and the name it sends is <strong>Bronze<\/strong>. If you want that test to assign a role, add a mapping for a tier called <code>Bronze<\/code>. Without it, the plugin falls back to your default role.<\/li>\n<li><strong>You have no default role set.<\/strong> The <em>single tip<\/em> and <em>first monthly<\/em> tests send no tier at all, so they can only ever use the default role. If that is empty and you rely purely on tier mappings, the supporter is still created as a WordPress user and the donation is still logged - only the role is skipped. The User log will show \"User created\" and \"Donation received\" but no \"Role assigned\".<\/li>\n<\/ul>\n\n<p>If the Request log is completely empty after a test, the request never reached WordPress. Check that the webhook URL in Ko-fi matches your site exactly, then open that URL in a browser:<\/p>\n\n<ul>\n<li><code>{\"error\":\"Method not allowed\"}<\/code> is the <strong>correct<\/strong> response. The endpoint only accepts the POST requests Ko-fi sends, and refuses anything else so that crawlers cannot fill your logs. Seeing this means the address is working.<\/li>\n<li>A \"Not Found\" or 404 page means the endpoint is not registered. Re-save your permalinks under <strong>Settings &gt; Permalinks<\/strong> to rebuild the rule, then try again.<\/li>\n<\/ul><\/dd>\n<dt id=\"a%20test%20says%20%22unauthorized%22%20or%20%22missing%20verification%20token%22.%20what%20now%3F\"><h3>A test says \"Unauthorized\" or \"Missing verification token\". What now?<\/h3><\/dt>\n<dd><p>The verification token in <strong>Members for Ko-fi &gt; Settings<\/strong> must match the one on Ko-fi's webhook page exactly. If you have ever regenerated it on Ko-fi, paste the new value into the plugin as well - Ko-fi will not warn you that the two no longer match, and real payments will be rejected the same way the test was.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20a%20supporter%27s%20role%20expires%3F\"><h3>What happens when a supporter's role expires?<\/h3><\/dt>\n<dd><p>Each time a payment arrives, the plugin records the date. If that date falls\nfurther in the past than the number of days you configure, a daily job removes\nthe role it assigned and stops tracking it. Their WordPress account stays, and\nso does any other role they have - only the role this plugin gave them is taken\naway.<\/p>\n\n<p>Set the number of days <strong>longer than your Ko-fi billing cycle<\/strong>, not equal to\nit. Ko-fi sends a webhook once when a payment happens and never retries, so if\none delivery is lost - a brief outage, a network problem - the next one is a\nwhole month away. With a 30-day setting, a single lost delivery costs that\nsupporter their access. Something around two billing cycles absorbs it: the\nnext successful payment refreshes the date before anything is removed.<\/p><\/dd>\n<dt id=\"why%20does%20a%20supporter%20have%20two%20roles%3F\"><h3>Why does a supporter have two roles?<\/h3><\/dt>\n<dd><p>The plugin adds its role to whatever the supporter already has, rather than\nreplacing it. New accounts get whatever WordPress assigns new users (usually\nSubscriber), and the plugin's role is added on top. When the role expires, only\nthe plugin's role is removed, which leaves the account intact.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20delete%20data%20on%20deactivation%3F\"><h3>Does this plugin delete data on deactivation?<\/h3><\/dt>\n<dd><p>No, the plugin does not delete any data on deactivation. However, you can manually delete data by uninstalling the plugin.<\/p><\/dd>\n<dt id=\"what%20personal%20data%20does%20this%20plugin%20store%3F\"><h3>What personal data does this plugin store?<\/h3><\/dt>\n<dd><p>Two tables of its own:<\/p>\n\n<ul>\n<li><strong>User log<\/strong> - the WordPress user ID, email address, what happened (user created, role assigned, role removed, donation received), the role, and the amount and currency.<\/li>\n<li><strong>Request log<\/strong> - the email address, tier name, amount, currency, the HTTP status, and the request Ko-fi sent. The verification token is never stored.<\/li>\n<\/ul>\n\n<p>Both are removed when you uninstall the plugin, along with its settings. Deactivating keeps them.<\/p>\n\n<p>The plugin does <strong>not<\/strong> currently register handlers for WordPress's privacy\nexport and erase tools, so a data request under GDPR or similar will not pick\nthese tables up automatically. If you need to remove a supporter's data, delete\ntheir WordPress user and clear the logs from the Logs tab.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Feature: Added automatic log cleanup with configurable retention period.<\/li>\n<li>Feature: Reorganized admin settings page with separate sections for Ko-fi Settings, Role Assignment, and Logging.<\/li>\n<li>Feature: Added support for viewing webhook request logs in addition to user logs.<\/li>\n<li>Enhancement: Renamed \"User Logs\" tab to \"Logs\" with dropdown to switch between User and Request logs.<\/li>\n<li>Enhancement: Renamed \"General\" tab to \"Settings\" for better clarity.<\/li>\n<li>Enhancement: Added daily cron job to automatically delete old logs based on retention settings.<\/li>\n<li>Enhancement: Settings now include \"Automatically Clear Logs\" (default: enabled) and \"Number of Days to Keep Logs\" (default: 30 days).<\/li>\n<li>Improvement: Better organization of settings with clear section headers.<\/li>\n<li>Fix: The request log table is now created when the plugin is updated, not only when it is first activated. Without this, updating from 1.0.x would have left the new Request log permanently empty.<\/li>\n<li>Fix: Donation messages containing quotes, backslashes or accented characters are no longer mangled, and are stored exactly as they were sent.<\/li>\n<li>Fix: Log cleanup now actually deletes old entries. It previously compared dates in two different formats and removed nothing.<\/li>\n<li>Fix: When a supporter changes tier, the role from their previous tier is now removed instead of being left in place.<\/li>\n<li>Fix: The log viewer no longer errors when an unexpected \"rows per page\" value is used.<\/li>\n<li>Fix: A role that no longer exists on the site is no longer assigned to a supporter.<\/li>\n<li>Fix: The \"Enable Expiry\" setting is now respected. Turning it off previously had no effect, and roles were still removed after the configured number of days.<\/li>\n<li>Fix: Searching the Request log now searches the request log. It previously returned results from the User log instead, whichever tab you were on.<\/li>\n<li>Security: The Ko-fi verification token is never stored in the request log, and is removed from the stored request details.<\/li>\n<li>Security: The verification token is no longer written to PHP error logs.<\/li>\n<li>Security: The webhook address now accepts only the request type Ko-fi actually sends, and ignores an address that keeps failing, so it cannot be used to fill your database. Genuine donations are never affected.<\/li>\n<li>Security: Tokens are compared in a way that does not reveal how much of a guess was correct.<\/li>\n<li>Improvement: Automated tests now run against a fresh install of the latest WordPress, including tests that send real donation requests over HTTP.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Build: Adjusted release packaging to exclude dev dependencies and include only production-ready vendor autoloader.<\/li>\n<li>No functional code changes for end users.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Support for Ko-fi webhooks.<\/li>\n<li>Automatic role assignment based on donations or memberships tiers.<\/li>\n<li>Logging of user actions in database.<\/li>\n<\/ul>","raw_excerpt":"Integrate with Ko-fi to manage WordPress users or roles via webhook.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/245535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=245535"}],"author":[{"embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/trudslev"}],"wp:attachment":[{"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=245535"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=245535"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=245535"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=245535"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=245535"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/nl.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=245535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}