Description
ShopSlot Free provides reliable instant booking with unlimited services for predictable appointment types. Configure services, weekly availability, lead times, booking horizons, blackout dates, buffers, customer details, and appointment status history from WordPress.
The separate ShopSlot Pro add-on adds request-and-approve workflows for complex jobs, maintained vehicle suggestions, service-specific staff routing, reusable notification templates, and optional customer notifications after staff edits.
The read-only Migration Center can identify familiar scheduling-plugin installations and produce sanitized inventory evidence without changing source data or exposing customer values. A guarded assisted-import runtime exists for controlled private-beta work with SSA, Amelia, and Bookly, but this release exposes no self-service import button or production cutover action. ShopSlot does not include invoicing, accounting, or inventory management.
Screenshots



![Publish an accessible customer booking form with the [shopslot_booking] shortcode.](https://ps.w.org/shopslot/assets/screenshot-4.png?rev=3685706)
[shopslot_booking] shortcode.
Installation
- Upload the
shopslotfolder to/wp-content/plugins/, or install the ZIP from Plugins > Add New > Upload Plugin. - Activate ShopSlot.
- Add services and configure availability under ShopSlot in the WordPress administrator.
- Place the
[shopslot_booking]shortcode on the page where customers should book.
Back up the site before replacing another scheduling system. The Migration Center in this release is read-only and does not modify another plugin’s records.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“ShopSlot” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “ShopSlot” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
0.19.1
- Make Save without notifying always save silently, even when an older form includes a checked notification value.
- Use explicit Save and notify customer / Save without notifying actions.
0.19.0
- Added a unified assisted-import gateway for SSA, Amelia, and Bookly that runs only inside the fail-closed protected-clone process with explicit operator approval, a verified source backup, outbound suppression, disabled cron, and a noindex environment.
- Retained the public Migration Center as a read-only inventory and sanitized audit surface with no import, rollback, cutover, checkout, or public-release action.
- Preserves imported source notification definitions with sending disabled; native ShopSlot templates remain a separate review decision and no legacy-template parity claim is made.
- Completed protected-clone import, idempotent rerun, nine-check reconciliation, scoped rollback, and repeated-rollback evidence for all three guarded connectors while keeping production cutover unavailable.
0.18.0
- Added a disconnected SSA-to-ShopSlot dry-run planner that transforms the protected snapshot entirely in memory and reconciles the proposed destination with nine privacy-safe checks.
- Requires an explicit request-or-instant booking policy and preserves notification definitions for parity without sending email, SMS, or webhooks.
- Produces a deterministic keyed dry-run fingerprint and rollback-record plan while keeping source values, manifests, and destination rows out of the report.
- Separates a faithful transformation proposal from import readiness: six current storage gaps remain named hard blockers, and real import and production cutover stay unavailable.
0.17.0
- Completed the first authorized, read-only ATRV protected-clone collection against real SSA data: 5 services, 63 appointments, and 4 notification rules normalized successfully with no writes or outbound sends.
- The
ssa-protected-clone-v5contract classifies every discovered source field as parity evidence, an explicit migration-design decision, or SSA bookkeeping; unknown future fields now block reconciliation. - Recorded the real ATRV baseline of 49 operational fields awaiting explicit import design and 12 SSA bookkeeping fields, with no raw field values returned.
- SSA legacy JSON-encoded empty custom-intake values now normalize as an empty field list instead of blocking a valid service.
- Valid empty notification sections now produce an honest complete-empty inventory rather than a contradictory unsafe-key diagnostic.
0.16.0
- Protected-clone reports now inventory mapped and safely named unmapped notification keys at the top-level settings, notification-section, and rule levels.
- Unmapped notification-setting values remain excluded from returned evidence and parity digests; only privacy-safe key labels and counts can enter the report.
- Unsafe notification-setting labels are redacted, counted, and hard-blocked with level-specific fixed diagnostics.
- A green run with any unmapped table column or notification-setting key is explicitly a coverage-review result, not approval to import or cut over.
0.15.0
- Protected-clone reports now inventory every mapped and safely named unmapped SSA service and appointment schema column without treating unmapped columns as parity evidence.
- Service status is truthfully labeled as mapped source evidence while ShopSlot active state is labeled as derived; booking mode remains a known uncollected concept.
- Missing appointment timezones are counted across the complete verified row set while continuing to hard-block and suppress the manifest; failed reads report the count as unknown rather than zero.
- Unsafe schema labels are redacted, counted, and treated as an incomplete-inventory block instead of being returned or silently discarded.
0.14.0
- Protected-clone reports now publish fixed field-coverage metadata and explicitly mark SSA booking mode as uncollected instead of inventing parity evidence.
- Blank SSA appointment timezones now fail closed; the collector no longer substitutes the protected clone’s WordPress timezone.
- Count-to-read drift now distinguishes rows appearing after COUNT from rows disappearing after COUNT while continuing to suppress all partial evidence.
0.13.0
- Added a disconnected, protected-clone-only SSA collector that reads exact source tables in bounded batches and passes protected rows directly to the privacy-safe normalizer in memory.
- All-empty evidence now requires positive table, prefix, schema, read-access, settings, and count verification; missing or partial evidence fails closed and suppresses the manifest.
- Collector reports contain only fixed diagnostic codes, counts, booleans, opaque IDs, and keyed digests while import, outbound communication, approval, and production cutover remain unavailable.
- Reconciliation failures now identify count, identity, and protected-field mismatch dimensions with privacy-safe booleans.
0.12.0
- Appointment reconciliation now binds each anonymous appointment identity to its canonical status and imported service relationship with a site-keyed digest.
- Swapping statuses or service links between otherwise valid appointments now fails reconciliation even when counts, IDs, status totals, and relationship totals still match.
- Missing appointment parity evidence fails closed while raw statuses, source keys, service links, customer values, and datetimes remain absent from reports.
0.11.0
- Added a pure in-memory SSA protected-clone normalizer that can build privacy-safe source and destination manifests from caller-supplied evidence without reading WordPress or enabling import.
- Source and destination identities are minted from the same SSA namespace and original SSA keys by construction; caller-supplied provider overrides are ignored.
- Service configuration now receives the same site-keyed protected-field reconciliation as customer, datetime, and notification evidence.
0.10.0
- Stable migration identities now use a versioned, site-keyed opaque format that cannot expose a provider key or human-readable label.
- The manifest builder rejects every legacy or plain-text identity, including otherwise safe-looking names, and requires its keyed reconciler dependency explicitly.
- Broken service relationships are classified as blocked while still remaining visible as negative destination reconciliation evidence.
0.9.0
- Added a provider-neutral protected-clone manifest builder for normalized service, appointment, notification, relationship, and rollback evidence.
- Protected values become site-keyed HMACs in memory and never appear in returned reports; malformed or duplicate evidence blocks the manifest.
- Added deterministic dry-run classifications while keeping import, outbound communication, approval, and production cutover unavailable.
0.8.0
- Added a read-only protected-clone reconciler with nine explicit service, appointment, relationship, status, privacy, notification, outbound-silence, and rollback checks.
- Site-keyed HMAC evidence keeps customer, datetime, and notification values out of reconciliation reports.
- Missing evidence now fails closed, while even a fully passing report cannot approve reconciliation or unlock production cutover.
- Bounded SSA status inventory to 50 aggregate labels and added a real SSA-to-Migration-Center contract test.
0.7.0
- Added the reusable seven-phase connector workflow and a deterministic inventory fingerprint for every Migration Center source.
- Added Pro-visible, schema-only SSA field-mapping candidates without reading appointment or customer rows.
- Added a complete protected-clone reconciliation checklist and six explicit approval gates from field mapping through production cutover.
- Kept every mapping unapproved, every gate locked, every source preserved, and every import, email, SMS, webhook, and production action unavailable.
0.6.0
- Added a provider-neutral, read-only Migration Center inventory to ShopSlot Free.
- Detects SSA, Amelia, Bookly, and Booking Calendar through table names and aggregate counts only; Calendly is identified as a planned external connector.
- Keeps the detailed sanitized SSA audit and export in Pro while every guided import write remains locked.
- Clearly labels available, planned, and external-planned connectors and never reads customer values or sends messages during discovery.
0.5.0
- Added safe extension points for Pro customer and staff booking templates.
- Added per-recipient staff delivery and audit logging so Pro can route services without exposing one staff address to another.
- Kept Free’s instant-booking subjects, wording, and administrator destination unchanged when no add-on is active.
0.4.0
- Added a privacy-safe SSA Migration Center audit that reads schema, aggregate counts, and redacted notification-routing metadata only.
- Added deterministic schema and aggregate fingerprints plus explicit readiness gates and stop reasons.
- Added a capability- and nonce-protected sanitized JSON audit download without storing the report.
- Kept production import, outbound notifications, webhooks, and source/destination writes fail-closed.
0.3.0
- Added protected UTF-8 appointment CSV export with spreadsheet-formula neutralization.
- Added explicit notification-log retention and preserve-by-default uninstall controls.
- Made opt-in uninstall multisite-aware and kept Pro settings owned by the Pro add-on.
- Removed the artificial active-service cap; request-and-approve remains a Pro workflow.
- Improved public and administrator keyboard focus, live status announcements, form semantics, and mobile table access.
0.2.2
- Added accessible, instance-safe vehicle suggestion fields with make-specific model filtering while preserving unrestricted manual entry.
0.2.1
- Added portable unique source identifiers for native appointments so repeat request-mode bookings behave consistently on MySQL and SQLite-backed WordPress test sites.
0.2.0
- Added generated, token-validated availability slots with weekly hours, lead time, booking horizon, blackout/extra-hours overrides, service buffers, and conflict revalidation.
0.1.0
- Initial private developer preview.
