Published : August 16, 2026

CVE-2026-12477: Gravity Booster <= 5.26 Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter PoC, Patch Analysis & Rule

Severity Medium (CVSS 4.4)
CWE 79
Vulnerable Version 5.26
Patched Version 6.0
Disclosed August 14, 2026

Analysis Overview

Atomic Edge analysis of CVE-2026-12477: This vulnerability is a Stored Cross-Site Scripting (XSS) flaw found in the Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress, identified in versions up to and including 5.26. The issue stems from insufficient input sanitization and output escaping on the ‘stylerSettings’ parameter, allowing authenticated users with editor-level permissions or higher to inject and execute arbitrary web scripts. The vulnerability has a CVSS score of 4.4 and affects multi-site installations or those where the ‘unfiltered_html’ capability has been disabled.

The root cause of the vulnerability lies in the plugin’s admin settings handling. The affected code path, primarily within the ‘styles-and-layouts-for-gravity-forms/admin-menu/EDD_SL_Plugin_Updater.php’ file, did not properly sanitize or escape the ‘stylerSettings’ parameter before storing it and later rendering it in the admin interface. While the provided diff focuses on the updater class, the core issue is in how the plugin’s settings API processes and outputs this specific parameter. The plugin failed to apply WordPress’s built-in sanitization functions like ‘sanitize_text_field’ or ‘esc_html’ to the ‘stylerSettings’ input, and failed to use escaping functions like ‘esc_attr’ or ‘wp_kses’ when rendering the stored value. This lack of handling allowed malicious HTML and JavaScript to be persisted in the database and subsequently executed in a user’s browser upon page load.

Exploitation of this vulnerability requires an attacker to have editor-level permissions on the WordPress site, which typically includes the ability to edit posts, pages, and manage site settings. The attack vector is the admin settings page for the Gravity Booster plugin. An authenticated attacker with these privileges would navigate to the plugin’s settings, locate the field associated with the ‘stylerSettings’ parameter, and inject a crafted payload containing JavaScript. For example, a payload such as ‘alert(document.cookie)’ or an event handler like ‘”>

‘ would be submitted through the POST request to the options.php or a similar settings-update endpoint. When an administrator or another editor later visits that settings page, the stored script executes in their browser context, potentially allowing for session hijacking, unauthorized actions, or further privilege escalation.

The patch addresses this vulnerability by introducing proper output escaping in the ‘EDD_SL_Plugin_Updater.php’ file, which is part of the plugin’s update notification display logic. Specifically, the fix wraps user-controlled data, such as ‘this->slug’ and ‘file’, with the ‘esc_attr()’ function when they are printed. This ensures that any malicious content within these values is rendered as inert text rather than executable HTML or JavaScript. The corrected code transforms the output from a raw, unescaped format to one that safely escapes HTML entities, thereby neutralizing XSS payloads. While the diff shown does not include the specific sanitization of the ‘stylerSettings’ parameter, it indicates the patch’s approach: thorough escaping of all dynamic output to prevent script injection.

The impact of this vulnerability is the execution of arbitrary JavaScript in the context of the WordPress admin area. An attacker with editor access could exploit this to perform actions such as injecting malicious scripts that steal administrator session cookies, create new admin accounts, or modify site content and settings. Since the attack requires high-privilege credentials, the direct impact is somewhat limited, but the potential for privilege escalation and full site compromise remains significant. The vulnerability’s effectiveness is constrained to multi-site installations or those where ‘unfiltered_html’ is disabled, which narrows its attack surface but does not eliminate the risk.

Differential between vulnerable and patched code

Below is a differential between the unpatched vulnerable code and the patched update, for reference.

Code Diff
--- a/styles-and-layouts-for-gravity-forms/admin-menu/EDD_SL_Plugin_Updater.php
+++ b/styles-and-layouts-for-gravity-forms/admin-menu/EDD_SL_Plugin_Updater.php
@@ -1,643 +1,648 @@
-<?php
-
-// Exit if accessed directly
-if ( ! defined( 'ABSPATH' ) ) {
-	exit;
-}
-
-/**
- * Allows plugins to use their own update API.
- *
- * @author Easy Digital Downloads
- * @version 1.9.1
- */
-class EDD_SL_Plugin_Updater {
-
-	private $api_url              = '';
-	private $api_data             = array();
-	private $plugin_file          = '';
-	private $name                 = '';
-	private $slug                 = '';
-	private $version              = '';
-	private $wp_override          = false;
-	private $beta                 = false;
-	private $failed_request_cache_key;
-
-	/**
-	 * Class constructor.
-	 *
-	 * @uses plugin_basename()
-	 * @uses hook()
-	 *
-	 * @param string  $_api_url     The URL pointing to the custom API endpoint.
-	 * @param string  $_plugin_file Path to the plugin file.
-	 * @param array   $_api_data    Optional data to send with API calls.
-	 */
-	public function __construct( $_api_url, $_plugin_file, $_api_data = null ) {
-
-		global $edd_plugin_data;
-
-		$this->api_url                  = trailingslashit( $_api_url );
-		$this->api_data                 = $_api_data;
-		$this->plugin_file              = $_plugin_file;
-		$this->name                     = plugin_basename( $_plugin_file );
-		$this->slug                     = basename( $_plugin_file, '.php' );
-		$this->version                  = $_api_data['version'];
-		$this->wp_override              = isset( $_api_data['wp_override'] ) ? (bool) $_api_data['wp_override'] : false;
-		$this->beta                     = ! empty( $this->api_data['beta'] ) ? true : false;
-		$this->failed_request_cache_key = 'edd_sl_failed_http_' . md5( $this->api_url );
-
-		$edd_plugin_data[ $this->slug ] = $this->api_data;
-
-		/**
-		 * Fires after the $edd_plugin_data is setup.
-		 *
-		 * @since x.x.x
-		 *
-		 * @param array $edd_plugin_data Array of EDD SL plugin data.
-		 */
-		do_action( 'post_edd_sl_plugin_updater_setup', $edd_plugin_data );
-
-		// Set up hooks.
-		$this->init();
-
-	}
-
-	/**
-	 * Set up WordPress filters to hook into WP's update process.
-	 *
-	 * @uses add_filter()
-	 *
-	 * @return void
-	 */
-	public function init() {
-
-		add_filter( 'pre_set_site_transient_update_plugins', array( $this, 'check_update' ) );
-		add_filter( 'plugins_api', array( $this, 'plugins_api_filter' ), 10, 3 );
-		add_action( 'after_plugin_row', array( $this, 'show_update_notification' ), 10, 2 );
-		add_action( 'admin_init', array( $this, 'show_changelog' ) );
-
-	}
-
-	/**
-	 * Check for Updates at the defined API endpoint and modify the update array.
-	 *
-	 * This function dives into the update API just when WordPress creates its update array,
-	 * then adds a custom API call and injects the custom plugin data retrieved from the API.
-	 * It is reassembled from parts of the native WordPress plugin update code.
-	 * See wp-includes/update.php line 121 for the original wp_update_plugins() function.
-	 *
-	 * @uses api_request()
-	 *
-	 * @param array   $_transient_data Update array build by WordPress.
-	 * @return array Modified update array with custom plugin data.
-	 */
-	public function check_update( $_transient_data ) {
-
-		global $pagenow;
-
-		if ( ! is_object( $_transient_data ) ) {
-			$_transient_data = new stdClass();
-		}
-
-		if ( ! empty( $_transient_data->response ) && ! empty( $_transient_data->response[ $this->name ] ) && false === $this->wp_override ) {
-			return $_transient_data;
-		}
-
-		$current = $this->get_repo_api_data();
-		if ( false !== $current && is_object( $current ) && isset( $current->new_version ) ) {
-			if ( version_compare( $this->version, $current->new_version, '<' ) ) {
-				$_transient_data->response[ $this->name ] = $current;
-			} else {
-				// Populating the no_update information is required to support auto-updates in WordPress 5.5.
-				$_transient_data->no_update[ $this->name ] = $current;
-			}
-		}
-		$_transient_data->last_checked           = time();
-		$_transient_data->checked[ $this->name ] = $this->version;
-
-		return $_transient_data;
-	}
-
-	/**
-	 * Get repo API data from store.
-	 * Save to cache.
-	 *
-	 * @return stdClass
-	 */
-	public function get_repo_api_data() {
-		$version_info = $this->get_cached_version_info();
-
-		if ( false === $version_info ) {
-			$version_info = $this->api_request(
-				'plugin_latest_version',
-				array(
-					'slug' => $this->slug,
-					'beta' => $this->beta,
-				)
-			);
-			if ( ! $version_info ) {
-				return false;
-			}
-
-			// This is required for your plugin to support auto-updates in WordPress 5.5.
-			$version_info->plugin = $this->name;
-			$version_info->id     = $this->name;
-
-			$this->set_version_info_cache( $version_info );
-		}
-
-		return $version_info;
-	}
-
-	/**
-	 * Show the update notification on multisite subsites.
-	 *
-	 * @param string  $file
-	 * @param array   $plugin
-	 */
-	public function show_update_notification( $file, $plugin ) {
-
-		// Return early if in the network admin, or if this is not a multisite install.
-		if ( is_network_admin() || ! is_multisite() ) {
-			return;
-		}
-
-		// Allow single site admins to see that an update is available.
-		if ( ! current_user_can( 'activate_plugins' ) ) {
-			return;
-		}
-
-		if ( $this->name !== $file ) {
-			return;
-		}
-
-		// Do not print any message if update does not exist.
-		$update_cache = get_site_transient( 'update_plugins' );
-
-		if ( ! isset( $update_cache->response[ $this->name ] ) ) {
-			if ( ! is_object( $update_cache ) ) {
-				$update_cache = new stdClass();
-			}
-			$update_cache->response[ $this->name ] = $this->get_repo_api_data();
-		}
-
-		// Return early if this plugin isn't in the transient->response or if the site is running the current or newer version of the plugin.
-		if ( empty( $update_cache->response[ $this->name ] ) || version_compare( $this->version, $update_cache->response[ $this->name ]->new_version, '>=' ) ) {
-			return;
-		}
-
-		printf(
-			'<tr class="plugin-update-tr %3$s" id="%1$s-update" data-slug="%1$s" data-plugin="%2$s">',
-			$this->slug,
-			$file,
-			in_array( $this->name, $this->get_active_plugins(), true ) ? 'active' : 'inactive'
-		);
-
-		echo '<td colspan="3" class="plugin-update colspanchange">';
-		echo '<div class="update-message notice inline notice-warning notice-alt"><p>';
-
-		$changelog_link = '';
-		if ( ! empty( $update_cache->response[ $this->name ]->sections->changelog ) ) {
-			$changelog_link = add_query_arg(
-				array(
-					'edd_sl_action' => 'view_plugin_changelog',
-					'plugin'        => urlencode( $this->name ),
-					'slug'          => urlencode( $this->slug ),
-					'TB_iframe'     => 'true',
-					'width'         => 77,
-					'height'        => 911,
-				),
-				self_admin_url( 'index.php' )
-			);
-		}
-		$update_link = add_query_arg(
-			array(
-				'action' => 'upgrade-plugin',
-				'plugin' => urlencode( $this->name ),
-			),
-			self_admin_url( 'update.php' )
-		);
-
-		printf(
-			/* translators: the plugin name. */
-			esc_html__( 'There is a new version of %1$s available.', 'easy-digital-downloads' ),
-			esc_html( $plugin['Name'] )
-		);
-
-		if ( ! current_user_can( 'update_plugins' ) ) {
-			echo ' ';
-			esc_html_e( 'Contact your network administrator to install the update.', 'easy-digital-downloads' );
-		} elseif ( empty( $update_cache->response[ $this->name ]->package ) && ! empty( $changelog_link ) ) {
-			echo ' ';
-			printf(
-				/* translators: 1. opening anchor tag, do not translate 2. the new plugin version 3. closing anchor tag, do not translate. */
-				__( '%1$sView version %2$s details%3$s.', 'easy-digital-downloads' ),
-				'<a target="_blank" class="thickbox open-plugin-details-modal" href="' . esc_url( $changelog_link ) . '">',
-				esc_html( $update_cache->response[ $this->name ]->new_version ),
-				'</a>'
-			);
-		} elseif ( ! empty( $changelog_link ) ) {
-			echo ' ';
-			printf(
-				__( '%1$sView version %2$s details%3$s or %4$supdate now%5$s.', 'easy-digital-downloads' ),
-				'<a target="_blank" class="thickbox open-plugin-details-modal" href="' . esc_url( $changelog_link ) . '">',
-				esc_html( $update_cache->response[ $this->name ]->new_version ),
-				'</a>',
-				'<a target="_blank" class="update-link" href="' . esc_url( wp_nonce_url( $update_link, 'upgrade-plugin_' . $file ) ) . '">',
-				'</a>'
-			);
-		} else {
-			printf(
-				' %1$s%2$s%3$s',
-				'<a target="_blank" class="update-link" href="' . esc_url( wp_nonce_url( $update_link, 'upgrade-plugin_' . $file ) ) . '">',
-				esc_html__( 'Update now.', 'easy-digital-downloads' ),
-				'</a>'
-			);
-		}
-
-		do_action( "in_plugin_update_message-{$file}", $plugin, $plugin );
-
-		echo '</p></div></td></tr>';
-	}
-
-	/**
-	 * Gets the plugins active in a multisite network.
-	 *
-	 * @return array
-	 */
-	private function get_active_plugins() {
-		$active_plugins         = (array) get_option( 'active_plugins' );
-		$active_network_plugins = (array) get_site_option( 'active_sitewide_plugins' );
-
-		return array_merge( $active_plugins, array_keys( $active_network_plugins ) );
-	}
-
-	/**
-	 * Updates information on the "View version x.x details" page with custom data.
-	 *
-	 * @uses api_request()
-	 *
-	 * @param mixed   $_data
-	 * @param string  $_action
-	 * @param object  $_args
-	 * @return object $_data
-	 */
-	public function plugins_api_filter( $_data, $_action = '', $_args = null ) {
-
-		if ( 'plugin_information' !== $_action ) {
-
-			return $_data;
-
-		}
-
-		if ( ! isset( $_args->slug ) || ( $_args->slug !== $this->slug ) ) {
-
-			return $_data;
-
-		}
-
-		$to_send = array(
-			'slug'   => $this->slug,
-			'is_ssl' => is_ssl(),
-			'fields' => array(
-				'banners' => array(),
-				'reviews' => false,
-				'icons'   => array(),
-			),
-		);
-
-		// Get the transient where we store the api request for this plugin for 24 hours
-		$edd_api_request_transient = $this->get_cached_version_info();
-
-		//If we have no transient-saved value, run the API, set a fresh transient with the API value, and return that value too right now.
-		if ( empty( $edd_api_request_transient ) ) {
-
-			$api_response = $this->api_request( 'plugin_information', $to_send );
-
-			// Expires in 3 hours
-			$this->set_version_info_cache( $api_response );
-
-			if ( false !== $api_response ) {
-				$_data = $api_response;
-			}
-		} else {
-			$_data = $edd_api_request_transient;
-		}
-
-		// Convert sections into an associative array, since we're getting an object, but Core expects an array.
-		if ( isset( $_data->sections ) && ! is_array( $_data->sections ) ) {
-			$_data->sections = $this->convert_object_to_array( $_data->sections );
-		}
-
-		// Convert banners into an associative array, since we're getting an object, but Core expects an array.
-		if ( isset( $_data->banners ) && ! is_array( $_data->banners ) ) {
-			$_data->banners = $this->convert_object_to_array( $_data->banners );
-		}
-
-		// Convert icons into an associative array, since we're getting an object, but Core expects an array.
-		if ( isset( $_data->icons ) && ! is_array( $_data->icons ) ) {
-			$_data->icons = $this->convert_object_to_array( $_data->icons );
-		}
-
-		// Convert contributors into an associative array, since we're getting an object, but Core expects an array.
-		if ( isset( $_data->contributors ) && ! is_array( $_data->contributors ) ) {
-			$_data->contributors = $this->convert_object_to_array( $_data->contributors );
-		}
-
-		if ( ! isset( $_data->plugin ) ) {
-			$_data->plugin = $this->name;
-		}
-
-		return $_data;
-	}
-
-	/**
-	 * Convert some objects to arrays when injecting data into the update API
-	 *
-	 * Some data like sections, banners, and icons are expected to be an associative array, however due to the JSON
-	 * decoding, they are objects. This method allows us to pass in the object and return an associative array.
-	 *
-	 * @since 3.6.5
-	 *
-	 * @param stdClass $data
-	 *
-	 * @return array
-	 */
-	private function convert_object_to_array( $data ) {
-		if ( ! is_array( $data ) && ! is_object( $data ) ) {
-			return array();
-		}
-		$new_data = array();
-		foreach ( $data as $key => $value ) {
-			$new_data[ $key ] = is_object( $value ) ? $this->convert_object_to_array( $value ) : $value;
-		}
-
-		return $new_data;
-	}
-
-	/**
-	 * Disable SSL verification in order to prevent download update failures
-	 *
-	 * @param array   $args
-	 * @param string  $url
-	 * @return object $array
-	 */
-	public function http_request_args( $args, $url ) {
-
-		if ( strpos( $url, 'https://' ) !== false && strpos( $url, 'edd_action=package_download' ) ) {
-			$args['sslverify'] = $this->verify_ssl();
-		}
-		return $args;
-
-	}
-
-	/**
-	 * Calls the API and, if successfull, returns the object delivered by the API.
-	 *
-	 * @uses get_bloginfo()
-	 * @uses wp_remote_post()
-	 * @uses is_wp_error()
-	 *
-	 * @param string  $_action The requested action.
-	 * @param array   $_data   Parameters for the API action.
-	 * @return false|object|void
-	 */
-	private function api_request( $_action, $_data ) {
-		$data = array_merge( $this->api_data, $_data );
-
-		if ( $data['slug'] !== $this->slug ) {
-			return;
-		}
-
-		// Don't allow a plugin to ping itself
-		if ( trailingslashit( home_url() ) === $this->api_url ) {
-			return false;
-		}
-
-		if ( $this->request_recently_failed() ) {
-			return false;
-		}
-
-		return $this->get_version_from_remote();
-	}
-
-	/**
-	 * Determines if a request has recently failed.
-	 *
-	 * @since 1.9.1
-	 *
-	 * @return bool
-	 */
-	private function request_recently_failed() {
-		$failed_request_details = get_option( $this->failed_request_cache_key );
-
-		// Request has never failed.
-		if ( empty( $failed_request_details ) || ! is_numeric( $failed_request_details ) ) {
-			return false;
-		}
-
-		/*
-		 * Request previously failed, but the timeout has expired.
-		 * This means we're allowed to try again.
-		 */
-		if ( time() > $failed_request_details ) {
-			delete_option( $this->failed_request_cache_key );
-
-			return false;
-		}
-
-		return true;
-	}
-
-	/**
-	 * Logs a failed HTTP request for this API URL.
-	 * We set a timestamp for 1 hour from now. This prevents future API requests from being
-	 * made to this domain for 1 hour. Once the timestamp is in the past, API requests
-	 * will be allowed again. This way if the site is down for some reason we don't bombard
-	 * it with failed API requests.
-	 *
-	 * @see EDD_SL_Plugin_Updater::request_recently_failed
-	 *
-	 * @since 1.9.1
-	 */
-	private function log_failed_request() {
-		update_option( $this->failed_request_cache_key, strtotime( '+1 hour' ) );
-	}
-
-	/**
-	 * If available, show the changelog for sites in a multisite install.
-	 */
-	public function show_changelog() {
-
-		if ( empty( $_REQUEST['edd_sl_action'] ) || 'view_plugin_changelog' !== $_REQUEST['edd_sl_action'] ) {
-			return;
-		}
-
-		if ( empty( $_REQUEST['plugin'] ) ) {
-			return;
-		}
-
-		if ( empty( $_REQUEST['slug'] ) || $this->slug !== $_REQUEST['slug'] ) {
-			return;
-		}
-
-		if ( ! current_user_can( 'update_plugins' ) ) {
-			wp_die( esc_html__( 'You do not have permission to install plugin updates', 'easy-digital-downloads' ), esc_html__( 'Error', 'easy-digital-downloads' ), array( 'response' => 403 ) );
-		}
-
-		$version_info = $this->get_repo_api_data();
-		if ( isset( $version_info->sections ) ) {
-			$sections = $this->convert_object_to_array( $version_info->sections );
-			if ( ! empty( $sections['changelog'] ) ) {
-				echo '<div style="background:#fff;padding:10px;">' . wp_kses_post( $sections['changelog'] ) . '</div>';
-			}
-		}
-
-		exit;
-	}
-
-	/**
-	 * Gets the current version information from the remote site.
-	 *
-	 * @return array|false
-	 */
-	private function get_version_from_remote() {
-		$api_params = array(
-			'edd_action'  => 'get_version',
-			'license'     => ! empty( $this->api_data['license'] ) ? $this->api_data['license'] : '',
-			'item_name'   => isset( $this->api_data['item_name'] ) ? $this->api_data['item_name'] : false,
-			'item_id'     => isset( $this->api_data['item_id'] ) ? $this->api_data['item_id'] : false,
-			'version'     => isset( $this->api_data['version'] ) ? $this->api_data['version'] : false,
-			'slug'        => $this->slug,
-			'author'      => $this->api_data['author'],
-			'url'         => home_url(),
-			'beta'        => $this->beta,
-			'php_version' => phpversion(),
-			'wp_version'  => get_bloginfo( 'version' ),
-		);
-
-		/**
-		 * Filters the parameters sent in the API request.
-		 *
-		 * @param array  $api_params        The array of data sent in the request.
-		 * @param array  $this->api_data    The array of data set up in the class constructor.
-		 * @param string $this->plugin_file The full path and filename of the file.
-		 */
-		$api_params = apply_filters( 'edd_sl_plugin_updater_api_params', $api_params, $this->api_data, $this->plugin_file );
-
-		$request = wp_remote_post(
-			$this->api_url,
-			array(
-				'timeout'   => 15,
-				'sslverify' => $this->verify_ssl(),
-				'body'      => $api_params,
-			)
-		);
-
-		if ( is_wp_error( $request ) || ( 200 !== wp_remote_retrieve_response_code( $request ) ) ) {
-			$this->log_failed_request();
-
-			return false;
-		}
-
-		$request = json_decode( wp_remote_retrieve_body( $request ) );
-
-		if ( $request && isset( $request->sections ) ) {
-			$request->sections = maybe_unserialize( $request->sections );
-		} else {
-			$request = false;
-		}
-
-		if ( $request && isset( $request->banners ) ) {
-			$request->banners = maybe_unserialize( $request->banners );
-		}
-
-		if ( $request && isset( $request->icons ) ) {
-			$request->icons = maybe_unserialize( $request->icons );
-		}
-
-		if ( ! empty( $request->sections ) ) {
-			foreach ( $request->sections as $key => $section ) {
-				$request->$key = (array) $section;
-			}
-		}
-
-		return $request;
-	}
-
-	/**
-	 * Get the version info from the cache, if it exists.
-	 *
-	 * @param string $cache_key
-	 * @return object
-	 */
-	public function get_cached_version_info( $cache_key = '' ) {
-
-		if ( empty( $cache_key ) ) {
-			$cache_key = $this->get_cache_key();
-		}
-
-		$cache = get_option( $cache_key );
-
-		// Cache is expired
-		if ( empty( $cache['timeout'] ) || time() > $cache['timeout'] ) {
-			return false;
-		}
-
-		// We need to turn the icons into an array, thanks to WP Core forcing these into an object at some point.
-		$cache['value'] = json_decode( $cache['value'] );
-		if ( ! empty( $cache['value']->icons ) ) {
-			$cache['value']->icons = (array) $cache['value']->icons;
-		}
-
-		return $cache['value'];
-
-	}
-
-	/**
-	 * Adds the plugin version information to the database.
-	 *
-	 * @param string $value
-	 * @param string $cache_key
-	 */
-	public function set_version_info_cache( $value = '', $cache_key = '' ) {
-
-		if ( empty( $cache_key ) ) {
-			$cache_key = $this->get_cache_key();
-		}
-
-		$data = array(
-			'timeout' => strtotime( '+3 hours', time() ),
-			'value'   => wp_json_encode( $value ),
-		);
-
-		update_option( $cache_key, $data, 'no' );
-
-		// Delete the duplicate option
-		delete_option( 'edd_api_request_' . md5( serialize( $this->slug . $this->api_data['license'] . $this->beta ) ) );
-	}
-
-	/**
-	 * Returns if the SSL of the store should be verified.
-	 *
-	 * @since  1.6.13
-	 * @return bool
-	 */
-	private function verify_ssl() {
-		return (bool) apply_filters( 'edd_sl_api_request_verify_ssl', true, $this );
-	}
-
-	/**
-	 * Gets the unique key (option name) for a plugin.
-	 *
-	 * @since 1.9.0
-	 * @return string
-	 */
-	private function get_cache_key() {
-		$string = $this->slug . $this->api_data['license'] . $this->beta;
-
-		return 'edd_sl_' . md5( serialize( $string ) );
-	}
-
-}
+<?php
+
+// Exit if accessed directly
+if ( ! defined( 'ABSPATH' ) ) {
+	exit;
+}
+
+/**
+ * Allows plugins to use their own update API.
+ *
+ * @author Easy Digital Downloads
+ * @version 1.9.1
+ */
+class EDD_SL_Plugin_Updater {
+
+	private $api_url              = '';
+	private $api_data             = array();
+	private $plugin_file          = '';
+	private $name                 = '';
+	private $slug                 = '';
+	private $version              = '';
+	private $wp_override          = false;
+	private $beta                 = false;
+	private $failed_request_cache_key;
+
+	/**
+	 * Class constructor.
+	 *
+	 * @uses plugin_basename()
+	 * @uses hook()
+	 *
+	 * @param string  $_api_url     The URL pointing to the custom API endpoint.
+	 * @param string  $_plugin_file Path to the plugin file.
+	 * @param array   $_api_data    Optional data to send with API calls.
+	 */
+	public function __construct( $_api_url, $_plugin_file, $_api_data = null ) {
+
+		global $edd_plugin_data;
+
+		$this->api_url                  = trailingslashit( $_api_url );
+		$this->api_data                 = $_api_data;
+		$this->plugin_file              = $_plugin_file;
+		$this->name                     = plugin_basename( $_plugin_file );
+		$this->slug                     = basename( $_plugin_file, '.php' );
+		$this->version                  = $_api_data['version'];
+		$this->wp_override              = isset( $_api_data['wp_override'] ) ? (bool) $_api_data['wp_override'] : false;
+		$this->beta                     = ! empty( $this->api_data['beta'] ) ? true : false;
+		$this->failed_request_cache_key = 'edd_sl_failed_http_' . md5( $this->api_url );
+
+		$edd_plugin_data[ $this->slug ] = $this->api_data;
+
+		/**
+		 * Fires after the $edd_plugin_data is setup.
+		 *
+		 * @since x.x.x
+		 *
+		 * @param array $edd_plugin_data Array of EDD SL plugin data.
+		 */
+		do_action( 'post_edd_sl_plugin_updater_setup', $edd_plugin_data );
+
+		// Set up hooks.
+		$this->init();
+
+	}
+
+	/**
+	 * Set up WordPress filters to hook into WP's update process.
+	 *
+	 * @uses add_filter()
+	 *
+	 * @return void
+	 */
+	public function init() {
+
+		add_filter( 'pre_set_site_transient_update_plugins', array( $this, 'check_update' ) );
+		add_filter( 'plugins_api', array( $this, 'plugins_api_filter' ), 10, 3 );
+		add_action( 'after_plugin_row', array( $this, 'show_update_notification' ), 10, 2 );
+		add_action( 'admin_init', array( $this, 'show_changelog' ) );
+
+	}
+
+	/**
+	 * Check for Updates at the defined API endpoint and modify the update array.
+	 *
+	 * This function dives into the update API just when WordPress creates its update array,
+	 * then adds a custom API call and injects the custom plugin data retrieved from the API.
+	 * It is reassembled from parts of the native WordPress plugin update code.
+	 * See wp-includes/update.php line 121 for the original wp_update_plugins() function.
+	 *
+	 * @uses api_request()
+	 *
+	 * @param array   $_transient_data Update array build by WordPress.
+	 * @return array Modified update array with custom plugin data.
+	 */
+	public function check_update( $_transient_data ) {
+
+		global $pagenow;
+
+		if ( ! is_object( $_transient_data ) ) {
+			$_transient_data = new stdClass();
+		}
+
+		if ( ! empty( $_transient_data->response ) && ! empty( $_transient_data->response[ $this->name ] ) && false === $this->wp_override ) {
+			return $_transient_data;
+		}
+
+		$current = $this->get_repo_api_data();
+		if ( false !== $current && is_object( $current ) && isset( $current->new_version ) ) {
+			if ( version_compare( $this->version, $current->new_version, '<' ) ) {
+				$_transient_data->response[ $this->name ] = $current;
+			} else {
+				// Populating the no_update information is required to support auto-updates in WordPress 5.5.
+				$_transient_data->no_update[ $this->name ] = $current;
+			}
+		}
+		$_transient_data->last_checked           = time();
+		$_transient_data->checked[ $this->name ] = $this->version;
+
+		return $_transient_data;
+	}
+
+	/**
+	 * Get repo API data from store.
+	 * Save to cache.
+	 *
+	 * @return stdClass
+	 */
+	public function get_repo_api_data() {
+		$version_info = $this->get_cached_version_info();
+
+		if ( false === $version_info ) {
+			$version_info = $this->api_request(
+				'plugin_latest_version',
+				array(
+					'slug' => $this->slug,
+					'beta' => $this->beta,
+				)
+			);
+			if ( ! $version_info ) {
+				return false;
+			}
+
+			// This is required for your plugin to support auto-updates in WordPress 5.5.
+			$version_info->plugin = $this->name;
+			$version_info->id     = $this->name;
+
+			$this->set_version_info_cache( $version_info );
+		}
+
+		return $version_info;
+	}
+
+	/**
+	 * Show the update notification on multisite subsites.
+	 *
+	 * @param string  $file
+	 * @param array   $plugin
+	 */
+	public function show_update_notification( $file, $plugin ) {
+
+		// Return early if in the network admin, or if this is not a multisite install.
+		if ( is_network_admin() || ! is_multisite() ) {
+			return;
+		}
+
+		// Allow single site admins to see that an update is available.
+		if ( ! current_user_can( 'activate_plugins' ) ) {
+			return;
+		}
+
+		if ( $this->name !== $file ) {
+			return;
+		}
+
+		// Do not print any message if update does not exist.
+		$update_cache = get_site_transient( 'update_plugins' );
+
+		if ( ! isset( $update_cache->response[ $this->name ] ) ) {
+			if ( ! is_object( $update_cache ) ) {
+				$update_cache = new stdClass();
+			}
+			$update_cache->response[ $this->name ] = $this->get_repo_api_data();
+		}
+
+		// Return early if this plugin isn't in the transient->response or if the site is running the current or newer version of the plugin.
+		if ( empty( $update_cache->response[ $this->name ] ) || version_compare( $this->version, $update_cache->response[ $this->name ]->new_version, '>=' ) ) {
+			return;
+		}
+
+		printf(
+			'<tr class="plugin-update-tr %3$s" id="%1$s-update" data-slug="%1$s" data-plugin="%2$s">',
+			esc_attr( $this->slug ),
+			esc_attr( $file ),
+			in_array( $this->name, $this->get_active_plugins(), true ) ? 'active' : 'inactive'
+		);
+
+		echo '<td colspan="3" class="plugin-update colspanchange">';
+		echo '<div class="update-message notice inline notice-warning notice-alt"><p>';
+
+		$changelog_link = '';
+		if ( ! empty( $update_cache->response[ $this->name ]->sections->changelog ) ) {
+			$changelog_link = add_query_arg(
+				array(
+					'edd_sl_action' => 'view_plugin_changelog',
+					'plugin'        => urlencode( $this->name ),
+					'slug'          => urlencode( $this->slug ),
+					'TB_iframe'     => 'true',
+					'width'         => 77,
+					'height'        => 911,
+				),
+				self_admin_url( 'index.php' )
+			);
+		}
+		$update_link = add_query_arg(
+			array(
+				'action' => 'upgrade-plugin',
+				'plugin' => urlencode( $this->name ),
+			),
+			self_admin_url( 'update.php' )
+		);
+
+		printf(
+			/* translators: the plugin name. */
+			esc_html__( 'There is a new version of %1$s available.', 'styles-and-layouts-for-gravity-forms' ),
+			esc_html( $plugin['Name'] )
+		);
+
+		if ( ! current_user_can( 'update_plugins' ) ) {
+			echo ' ';
+			esc_html_e( 'Contact your network administrator to install the update.', 'styles-and-layouts-for-gravity-forms' );
+		} elseif ( empty( $update_cache->response[ $this->name ]->package ) && ! empty( $changelog_link ) ) {
+			echo ' ';
+			echo wp_kses_post(
+				sprintf(
+					/* translators: 1. opening anchor tag, do not translate 2. the new plugin version 3. closing anchor tag, do not translate. */
+					__( '%1$sView version %2$s details%3$s.', 'styles-and-layouts-for-gravity-forms' ),
+					'<a target="_blank" class="thickbox open-plugin-details-modal" href="' . esc_url( $changelog_link ) . '">',
+					esc_html( $update_cache->response[ $this->name ]->new_version ),
+					'</a>'
+				)
+			);
+		} elseif ( ! empty( $changelog_link ) ) {
+			echo ' ';
+			echo wp_kses_post(
+				sprintf(
+					/* translators: 1: opening anchor tag for the changelog, 2: version number, 3: closing anchor tag, 4: opening anchor tag for the update link, 5: closing anchor tag. */
+					__( '%1$sView version %2$s details%3$s or %4$supdate now%5$s.', 'styles-and-layouts-for-gravity-forms' ),
+					'<a target="_blank" class="thickbox open-plugin-details-modal" href="' . esc_url( $changelog_link ) . '">',
+					esc_html( $update_cache->response[ $this->name ]->new_version ),
+					'</a>',
+					'<a target="_blank" class="update-link" href="' . esc_url( wp_nonce_url( $update_link, 'upgrade-plugin_' . $file ) ) . '">',
+					'</a>'
+				)
+			);
+		} else {
+			printf(
+				' %1$s%2$s%3$s',
+				'<a target="_blank" class="update-link" href="' . esc_url( wp_nonce_url( $update_link, 'upgrade-plugin_' . $file ) ) . '">',
+				esc_html__( 'Update now.', 'styles-and-layouts-for-gravity-forms' ),
+				'</a>'
+			);
+		}
+
+		do_action( "in_plugin_update_message-{$file}", $plugin, $plugin );
+
+		echo '</p></div></td></tr>';
+	}
+
+	/**
+	 * Gets the plugins active in a multisite network.
+	 *
+	 * @return array
+	 */
+	private function get_active_plugins() {
+		$active_plugins         = (array) get_option( 'active_plugins' );
+		$active_network_plugins = (array) get_site_option( 'active_sitewide_plugins' );
+
+		return array_merge( $active_plugins, array_keys( $active_network_plugins ) );
+	}
+
+	/**
+	 * Updates information on the "View version x.x details" page with custom data.
+	 *
+	 * @uses api_request()
+	 *
+	 * @param mixed   $_data
+	 * @param string  $_action
+	 * @param object  $_args
+	 * @return object $_data
+	 */
+	public function plugins_api_filter( $_data, $_action = '', $_args = null ) {
+
+		if ( 'plugin_information' !== $_action ) {
+
+			return $_data;
+
+		}
+
+		if ( ! isset( $_args->slug ) || ( $_args->slug !== $this->slug ) ) {
+
+			return $_data;
+
+		}
+
+		$to_send = array(
+			'slug'   => $this->slug,
+			'is_ssl' => is_ssl(),
+			'fields' => array(
+				'banners' => array(),
+				'reviews' => false,
+				'icons'   => array(),
+			),
+		);
+
+		// Get the transient where we store the api request for this plugin for 24 hours
+		$edd_api_request_transient = $this->get_cached_version_info();
+
+		//If we have no transient-saved value, run the API, set a fresh transient with the API value, and return that value too right now.
+		if ( empty( $edd_api_request_transient ) ) {
+
+			$api_response = $this->api_request( 'plugin_information', $to_send );
+
+			// Expires in 3 hours
+			$this->set_version_info_cache( $api_response );
+
+			if ( false !== $api_response ) {
+				$_data = $api_response;
+			}
+		} else {
+			$_data = $edd_api_request_transient;
+		}
+
+		// Convert sections into an associative array, since we're getting an object, but Core expects an array.
+		if ( isset( $_data->sections ) && ! is_array( $_data->sections ) ) {
+			$_data->sections = $this->convert_object_to_array( $_data->sections );
+		}
+
+		// Convert banners into an associative array, since we're getting an object, but Core expects an array.
+		if ( isset( $_data->banners ) && ! is_array( $_data->banners ) ) {
+			$_data->banners = $this->convert_object_to_array( $_data->banners );
+		}
+
+		// Convert icons into an associative array, since we're getting an object, but Core expects an array.
+		if ( isset( $_data->icons ) && ! is_array( $_data->icons ) ) {
+			$_data->icons = $this->convert_object_to_array( $_data->icons );
+		}
+
+		// Convert contributors into an associative array, since we're getting an object, but Core expects an array.
+		if ( isset( $_data->contributors ) && ! is_array( $_data->contributors ) ) {
+			$_data->contributors = $this->convert_object_to_array( $_data->contributors );
+		}
+
+		if ( ! isset( $_data->plugin ) ) {
+			$_data->plugin = $this->name;
+		}
+
+		return $_data;
+	}
+
+	/**
+	 * Convert some objects to arrays when injecting data into the update API
+	 *
+	 * Some data like sections, banners, and icons are expected to be an associative array, however due to the JSON
+	 * decoding, they are objects. This method allows us to pass in the object and return an associative array.
+	 *
+	 * @since 3.6.5
+	 *
+	 * @param stdClass $data
+	 *
+	 * @return array
+	 */
+	private function convert_object_to_array( $data ) {
+		if ( ! is_array( $data ) && ! is_object( $data ) ) {
+			return array();
+		}
+		$new_data = array();
+		foreach ( $data as $key => $value ) {
+			$new_data[ $key ] = is_object( $value ) ? $this->convert_object_to_array( $value ) : $value;
+		}
+
+		return $new_data;
+	}
+
+	/**
+	 * Disable SSL verification in order to prevent download update failures
+	 *
+	 * @param array   $args
+	 * @param string  $url
+	 * @return object $array
+	 */
+	public function http_request_args( $args, $url ) {
+
+		if ( strpos( $url, 'https://' ) !== false && strpos( $url, 'edd_action=package_download' ) ) {
+			$args['sslverify'] = $this->verify_ssl();
+		}
+		return $args;
+
+	}
+
+	/**
+	 * Calls the API and, if successfull, returns the object delivered by the API.
+	 *
+	 * @uses get_bloginfo()
+	 * @uses wp_remote_post()
+	 * @uses is_wp_error()
+	 *
+	 * @param string  $_action The requested action.
+	 * @param array   $_data   Parameters for the API action.
+	 * @return false|object|void
+	 */
+	private function api_request( $_action, $_data ) {
+		$data = array_merge( $this->api_data, $_data );
+
+		if ( $data['slug'] !== $this->slug ) {
+			return;
+		}
+
+		// Don't allow a plugin to ping itself
+		if ( trailingslashit( home_url() ) === $this->api_url ) {
+			return false;
+		}
+
+		if ( $this->request_recently_failed() ) {
+			return false;
+		}
+
+		return $this->get_version_from_remote();
+	}
+
+	/**
+	 * Determines if a request has recently failed.
+	 *
+	 * @since 1.9.1
+	 *
+	 * @return bool
+	 */
+	private function request_recently_failed() {
+		$failed_request_details = get_option( $this->failed_request_cache_key );
+
+		// Request has never failed.
+		if ( empty( $failed_request_details ) || ! is_numeric( $failed_request_details ) ) {
+			return false;
+		}
+
+		/*
+		 * Request previously failed, but the timeout has expired.
+		 * This means we're allowed to try again.
+		 */
+		if ( time() > $failed_request_details ) {
+			delete_option( $this->failed_request_cache_key );
+
+			return false;
+		}
+
+		return true;
+	}
+
+	/**
+	 * Logs a failed HTTP request for this API URL.
+	 * We set a timestamp for 1 hour from now. This prevents future API requests from being
+	 * made to this domain for 1 hour. Once the timestamp is in the past, API requests
+	 * will be allowed again. This way if the site is down for some reason we don't bombard
+	 * it with failed API requests.
+	 *
+	 * @see EDD_SL_Plugin_Updater::request_recently_failed
+	 *
+	 * @since 1.9.1
+	 */
+	private function log_failed_request() {
+		update_option( $this->failed_request_cache_key, strtotime( '+1 hour' ) );
+	}
+
+	/**
+	 * If available, show the changelog for sites in a multisite install.
+	 */
+	public function show_changelog() {
+
+		if ( empty( $_REQUEST['edd_sl_action'] ) || 'view_plugin_changelog' !== $_REQUEST['edd_sl_action'] ) {
+			return;
+		}
+
+		if ( empty( $_REQUEST['plugin'] ) ) {
+			return;
+		}
+
+		if ( empty( $_REQUEST['slug'] ) || $this->slug !== $_REQUEST['slug'] ) {
+			return;
+		}
+
+		if ( ! current_user_can( 'update_plugins' ) ) {
+			wp_die( esc_html__( 'You do not have permission to install plugin updates', 'styles-and-layouts-for-gravity-forms' ), esc_html__( 'Error', 'styles-and-layouts-for-gravity-forms' ), array( 'response' => 403 ) );
+		}
+
+		$version_info = $this->get_repo_api_data();
+		if ( isset( $version_info->sections ) ) {
+			$sections = $this->convert_object_to_array( $version_info->sections );
+			if ( ! empty( $sections['changelog'] ) ) {
+				echo '<div style="background:#fff;padding:10px;">' . wp_kses_post( $sections['changelog'] ) . '</div>';
+			}
+		}
+
+		exit;
+	}
+
+	/**
+	 * Gets the current version information from the remote site.
+	 *
+	 * @return array|false
+	 */
+	private function get_version_from_remote() {
+		$api_params = array(
+			'edd_action'  => 'get_version',
+			'license'     => ! empty( $this->api_data['license'] ) ? $this->api_data['license'] : '',
+			'item_name'   => isset( $this->api_data['item_name'] ) ? $this->api_data['item_name'] : false,
+			'item_id'     => isset( $this->api_data['item_id'] ) ? $this->api_data['item_id'] : false,
+			'version'     => isset( $this->api_data['version'] ) ? $this->api_data['version'] : false,
+			'slug'        => $this->slug,
+			'author'      => $this->api_data['author'],
+			'url'         => home_url(),
+			'beta'        => $this->beta,
+			'php_version' => phpversion(),
+			'wp_version'  => get_bloginfo( 'version' ),
+		);
+
+		/**
+		 * Filters the parameters sent in the API request.
+		 *
+		 * @param array  $api_params        The array of data sent in the request.
+		 * @param array  $this->api_data    The array of data set up in the class constructor.
+		 * @param string $this->plugin_file The full path and filename of the file.
+		 */
+		$api_params = apply_filters( 'edd_sl_plugin_updater_api_params', $api_params, $this->api_data, $this->plugin_file );
+
+		$request = wp_remote_post(
+			$this->api_url,
+			array(
+				'timeout'   => 15,
+				'sslverify' => $this->verify_ssl(),
+				'body'      => $api_params,
+			)
+		);
+
+		if ( is_wp_error( $request ) || ( 200 !== wp_remote_retrieve_response_code( $request ) ) ) {
+			$this->log_failed_request();
+
+			return false;
+		}
+
+		$request = json_decode( wp_remote_retrieve_body( $request ) );
+
+		if ( $request && isset( $request->sections ) ) {
+			$request->sections = maybe_unserialize( $request->sections );
+		} else {
+			$request = false;
+		}
+
+		if ( $request && isset( $request->banners ) ) {
+			$request->banners = maybe_unserialize( $request->banners );
+		}
+
+		if ( $request && isset( $request->icons ) ) {
+			$request->icons = maybe_unserialize( $request->icons );
+		}
+
+		if ( ! empty( $request->sections ) ) {
+			foreach ( $request->sections as $key => $section ) {
+				$request->$key = (array) $section;
+			}
+		}
+
+		return $request;
+	}
+
+	/**
+	 * Get the version info from the cache, if it exists.
+	 *
+	 * @param string $cache_key
+	 * @return object
+	 */
+	public function get_cached_version_info( $cache_key = '' ) {
+
+		if ( empty( $cache_key ) ) {
+			$cache_key = $this->get_cache_key();
+		}
+
+		$cache = get_option( $cache_key );
+
+		// Cache is expired
+		if ( empty( $cache['timeout'] ) || time() > $cache['timeout'] ) {
+			return false;
+		}
+
+		// We need to turn the icons into an array, thanks to WP Core forcing these into an object at some point.
+		$cache['value'] = json_decode( $cache['value'] );
+		if ( ! empty( $cache['value']->icons ) ) {
+			$cache['value']->icons = (array) $cache['value']->icons;
+		}
+
+		return $cache['value'];
+
+	}
+
+	/**
+	 * Adds the plugin version information to the database.
+	 *
+	 * @param string $value
+	 * @param string $cache_key
+	 */
+	public function set_version_info_cache( $value = '', $cache_key = '' ) {
+
+		if ( empty( $cache_key ) ) {
+			$cache_key = $this->get_cache_key();
+		}
+
+		$data = array(
+			'timeout' => strtotime( '+3 hours', time() ),
+			'value'   => wp_json_encode( $value ),
+		);
+
+		update_option( $cache_key, $data, 'no' );
+
+		// Delete the duplicate option
+		delete_option( 'edd_api_request_' . md5( serialize( $this->slug . $this->api_data['license'] . $this->beta ) ) );
+	}
+
+	/**
+	 * Returns if the SSL of the store should be verified.
+	 *
+	 * @since  1.6.13
+	 * @return bool
+	 */
+	private function verify_ssl() {
+		return (bool) apply_filters( 'edd_sl_api_request_verify_ssl', true, $this );
+	}
+
+	/**
+	 * Gets the unique key (option name) for a plugin.
+	 *
+	 * @since 1.9.0
+	 * @return string
+	 */
+	private function get_cache_key() {
+		$string = $this->slug . $this->api_data['license'] . $this->beta;
+
+		return 'edd_sl_' . md5( serialize( $string ) );
+	}
+
+}
--- a/styles-and-layouts-for-gravity-forms/admin-menu/class-gf-stla-welcome-page.php
+++ b/styles-and-layouts-for-gravity-forms/admin-menu/class-gf-stla-welcome-page.php
@@ -1,207 +1,211 @@
-<?php
-/**
- * Render the welcome page.
- */
-
-class Gf_Stla_Welcome_Page {
-
-	/**
-	 * Execute the actions and filters.
-	 */
-	public function __construct() {
-		add_action( 'admin_menu', array( $this, 'register_menu' ) );
-	}
-
-	/**
-	 * Register
-	 *
-	 * @return void
-	 */
-	public function register_menu() {
-		add_submenu_page( 'stla_licenses', 'Documentation', 'Documentation', 'manage_options', 'stla-documentation', array( $this, 'show_documentation' ) );
-	}
-
-	/**
-	 * The HTML of welcome page.
-	 *
-	 * @return void
-	 */
-	public function show_documentation() {
-		$gf_stla_version = get_plugin_data( GF_STLA_DIR . '/styles-layouts-gravity-forms.php', $markup = true, $translate = true );
-
-		?>
-
-		<div class="stla-wel-page-wrap" >
-			<div class="stla-wel-header-info">
-				<img class="stla-intro-image" src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/style&layoutlogo.png'; ?>" />
-				<div class="stla-wel-heading-text stla-wel-padding-container">
-					<h2 class="stla-welcome-heading">Welcome to Styles & Layouts for Gravity Forms</h2>
-					<p >Thank you for choosing Styles & Layout for Gravity Forms - the most used, cost free plugin that let you style Gravity forms without any problem.</p>
-				</div>
-
-				<div class="stla-wel-video-section">
-					<?php add_thickbox(); ?>
-
-					<a href="https://www.youtube.com/embed/bkiBdaxIPjY?autoplay=1?TB_iframe=true&width=1180&height=750" class="thickbox">
-					<img class="" src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/video-image.jpg'; ?>" />
-					</a>
-				</div>
-
-			</div>
-			<div class="stla-wel-feature">
-				<div class="stla-wel-padding-container">
-					<h2> Plugin Features & Addon</h2>
-					<p>It comes with 100+ options to customize various parts of gravity form like form wrapper, form header, form title and description, submit button, radio inputs, checkbox inputs, paragraph textarea, labels, section breaks, descriptions, text inputs , dropdown menus, labels, sub labels, placeholders, list fields, confirmation message, error messages and more.
-					</p>
-					<div class="stla-wel-feature-info-cont">
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome-feature-icon-1.png'; ?>">
-							<h5>100+ Styling options</h5>
-							<h6>Easily create an amazing form designs in just a few minutes without writing any code.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/preview.png'; ?>">
-							<h5>Live Preview Changes</h5>
-							<h6>All the changes you make are previed instantly without any need to refresh the page.</h6>
-						</div>
-
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/responsive.png'; ?>">
-							<h5>Responsive Options</h5>
-							<h6>Style your form differently for Desktops, Tablets and Mobile devices.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/individual-from.png'; ?>">
-							<h5>Style Individual Form</h5>
-							<h6>Each form can be designed separtely even if they are added into same page</h6>
-						</div>
-
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/theme.png'; ?>">
-							<h5>Compatible with Every Theme</h5>
-							<h6>Ability to overwrite default theme styles by making Styles & Layouts design as important.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/easy-to-use.png'; ?>">
-							<h5>Easy to Use</h5>
-							<h6>Easy to use controls like color picker, range slider and ability to give values in px, %, rem, em etc.</h6>
-						</div>
-
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/flexible.png'; ?>">
-							<h5>Flexible</h5>
-							<h6>Multiple settings for each field type to create the design you want to have.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/customer-service.png'; ?>">
-							<h5><a href="https://wpmonks.com/contact-us/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Premium Support</a></h5>
-							<h6>Need custom design, functionality or want to report an issue then get in touch.</h6>
-						</div>
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/recommend.png'; ?>">
-							<h5><a href="https://www.gravityforms.com/community/styles-layouts/" target="_blank">Recommended by Gravity Forms</a></h5>
-							<h6>Gravity Forms recommend using Styles & Layouts if you don't want to write custom CSS.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/addons.png'; ?>">
-							<h5><a href="https://wpmonks.com/downloads/addon-bundle/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Addons With Rich Settings</a></h5>
-							<h6>Carefully designed set of addons to make your forms look amazing with minimal effort.</h6>
-						</div>
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/material.png'; ?>">
-							<h5><a href="https://wpmonks.com/downloads/material-design/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Material Design</a></h5>
-							<h6>Implement Material design on your form with single click.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/bootstrap-icon.png'; ?>">
-							<h5><a href="https://wpmonks.com/downloads/gravity-forms-bootstrap-addon/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Bootstrap</a></h5>
-							<h6>Implement Bootstrap design on your form with single click.</h6>
-						</div>
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/field-icons.png'; ?>">
-							<h5><a href="http://wpmonks.com/downloads/field-icons/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Field Icons</a></h5>
-							<h6>Add image or fontawesome icons to form fields and position them.</h6>
-						</div>
-						<div class="stla-wel-right-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/tooltip.png'; ?>">
-							<h5><a href="http://wpmonks.com/downloads/tooltips/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Tooltip</a></h5>
-							<h6>Add helpful tips for each form field with a wide range of tooltip icon selection</h6>
-						</div>
-						<div class="stla-wel-left-cont stla-wel-feature-box">
-							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/cs-theme.png'; ?>">
-							<h5><a href="http://wpmonks.com/downloads/custom-themes/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Custom Themes</a></h5>
-							<h6>Save your current form theme design and implement it on other forms in one click.</h6>
-						</div>
-					</div>
-				</div>
-
-				<div class="stla-wel-addon-feature stla-wel-padding-container">
-					<div class="stla-update-left">
-						<h2> Addon Bundle</h2>
-						<ul>
-							<li><span class="dashicons dashicons-yes"></span> Material Design </li>
-							<li><span class="dashicons dashicons-yes"></span> Bootstrap </li>
-							<li><span class="dashicons dashicons-yes"></span> Theme Pack </li>
-							<li><span class="dashicons dashicons-yes"></span> Tooltips </li>
-							<li><span class="dashicons dashicons-yes"></span> Field Icons </li>
-							<li><span class="dashicons dashicons-yes"></span> Custom Themes </li>
-							<li><span class="dashicons dashicons-yes"></span> Premium Support </li>
-
-						</ul>
-					</div>
-					<div class="stla-update-right">
-						<h2> <span> PRO</span> </h2>
-						<div class="stla-wel-addon-price">
-							<span class="stla-wel-amount">59.99</span>
-							<br>
-							<span  class="stla-wel-term">per year</span>
-						</div>
-						<a class="stla-wel-btn" href="http://wpmonks.com/downloads/addon-bundle/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin">Buy Now</a>
-					</div>
-				</div>
-				<div class="stla-wel-testimonials stla-wel-padding-container">
-					<h2> Testimonials </h2>
-					<div class="stla-wel-testimonial-block stla-first-test-block">
-						<p>
-						"I just started using Gravity Forms today because Zoho web forms were not responsive, and our forms looked terrible on mobile devices. So, I bought Gravity Forms with the Zoho Add On. Works great! But, the form was really difficult to design. I looked for help, and found this plugin. Styles and Layouts Gravity Forms really helped make the forms look good on any device. I highly recommend this plugin, especially for first time Gravity Forms users."<span class="stla-testimonial-author"> -ltcshop</span>
-						</p>
-					</div>
-					<div class="stla-wel-testimonial-block">
-						<p>
-						"Currently using this on a few sites. Haven’t had any significant issues, and developer was very responsive when I suggested an improvement. It’s a great time-saver."<span class="stla-testimonial-author"> -ebeacon</span>
-						</p>
-					</div>
-				</div>
-
-				<div class="sk-donate-cont stla-wel-padding-container">
-					<div class="stla-wel-btn-wrapper">
-						<div class="stla-wel-left-cont">
-							<a href="https://paypal.me/wpmonks" class="stla-wel-btn stla-wel-btn-block"> Donate to Support Plugin</a>
-						</div>
-						<div class="stla-wel-right-cont">
-							<a href="https://twitter.com/wp_monk" class="stla-wel-btn stla-wel-btn-custom">
-								<span class="stla-wel-custom-btn-text"> Follow us on Twitter
-									<span class="dashicons dashicons-arrow-right"></span>
-								<span>
-							</a>
-						</div>
-					</div>
-				</div>
-			</div>
-			<div class="stla-wel-review-cont" style="background:url('<?php echo esc_url( GF_STLA_URL ) . '/css/images/suggestions.jpg'; ?>')">
-				<div class="stla-wel-padding-container">
-					<div class="stla-update-left">
-						<h2> Let us Know your Suggestions.</h2>
-						<p>
-						Your suggestion and reviews are valuable for us. Let us know if you have any problem with plugin.
-						</p>
-						<a class="stla-wel-btn stla-wel-btn-space" href="https://wpmonks.com/contact-us/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin">Contact Us</a>
-					</div>
-				</div>
-			</div>
-		</div>
-		<?php
-	}
-}
-
-new Gf_Stla_Welcome_Page();
+<?php
+
+if ( ! defined( 'ABSPATH' ) ) {
+	exit;
+}
+/**
+ * Render the welcome page.
+ */
+
+class Gf_Stla_Welcome_Page {
+
+	/**
+	 * Execute the actions and filters.
+	 */
+	public function __construct() {
+		add_action( 'admin_menu', array( $this, 'register_menu' ) );
+	}
+
+	/**
+	 * Register
+	 *
+	 * @return void
+	 */
+	public function register_menu() {
+		add_submenu_page( 'stla_licenses', 'Documentation', 'Documentation', 'manage_options', 'stla-documentation', array( $this, 'show_documentation' ) );
+	}
+
+	/**
+	 * The HTML of welcome page.
+	 *
+	 * @return void
+	 */
+	public function show_documentation() {
+		$gf_stla_version = get_plugin_data( GF_STLA_DIR . '/styles-layouts-gravity-forms.php', $markup = true, $translate = true );
+
+		?>
+
+		<div class="stla-wel-page-wrap" >
+			<div class="stla-wel-header-info">
+				<img class="stla-intro-image" src="<?php echo esc_url( GF_STLA_URL . '/css/images/style-layout-logo.png' ); ?>" />
+				<div class="stla-wel-heading-text stla-wel-padding-container">
+					<h2 class="stla-welcome-heading">Welcome to Styles & Layouts for Gravity Forms</h2>
+					<p >Thank you for choosing Styles & Layout for Gravity Forms - the most used, cost free plugin that let you style Gravity forms without any problem.</p>
+				</div>
+
+				<div class="stla-wel-video-section">
+					<?php add_thickbox(); ?>
+
+					<a href="https://www.youtube.com/embed/bkiBdaxIPjY?autoplay=1?TB_iframe=true&width=1180&height=750" class="thickbox">
+					<img class="" src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/video-image.jpg'; ?>" />
+					</a>
+				</div>
+
+			</div>
+			<div class="stla-wel-feature">
+				<div class="stla-wel-padding-container">
+					<h2> Plugin Features & Addon</h2>
+					<p>It comes with 100+ options to customize various parts of gravity form like form wrapper, form header, form title and description, submit button, radio inputs, checkbox inputs, paragraph textarea, labels, section breaks, descriptions, text inputs , dropdown menus, labels, sub labels, placeholders, list fields, confirmation message, error messages and more.
+					</p>
+					<div class="stla-wel-feature-info-cont">
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome-feature-icon-1.png'; ?>">
+							<h5>100+ Styling options</h5>
+							<h6>Easily create an amazing form designs in just a few minutes without writing any code.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/preview.png'; ?>">
+							<h5>Live Preview Changes</h5>
+							<h6>All the changes you make are previed instantly without any need to refresh the page.</h6>
+						</div>
+
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/responsive.png'; ?>">
+							<h5>Responsive Options</h5>
+							<h6>Style your form differently for Desktops, Tablets and Mobile devices.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/individual-from.png'; ?>">
+							<h5>Style Individual Form</h5>
+							<h6>Each form can be designed separtely even if they are added into same page</h6>
+						</div>
+
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/theme.png'; ?>">
+							<h5>Compatible with Every Theme</h5>
+							<h6>Ability to overwrite default theme styles by making Styles & Layouts design as important.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/easy-to-use.png'; ?>">
+							<h5>Easy to Use</h5>
+							<h6>Easy to use controls like color picker, range slider and ability to give values in px, %, rem, em etc.</h6>
+						</div>
+
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/flexible.png'; ?>">
+							<h5>Flexible</h5>
+							<h6>Multiple settings for each field type to create the design you want to have.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/customer-service.png'; ?>">
+							<h5><a href="https://wpmonks.com/contact-us/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Premium Support</a></h5>
+							<h6>Need custom design, functionality or want to report an issue then get in touch.</h6>
+						</div>
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/recommend.png'; ?>">
+							<h5><a href="https://www.gravityforms.com/community/styles-layouts/" target="_blank">Recommended by Gravity Forms</a></h5>
+							<h6>Gravity Forms recommend using Styles & Layouts if you don't want to write custom CSS.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/addons.png'; ?>">
+							<h5><a href="https://wpmonks.com/downloads/addon-bundle/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Addons With Rich Settings</a></h5>
+							<h6>Carefully designed set of addons to make your forms look amazing with minimal effort.</h6>
+						</div>
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/material.png'; ?>">
+							<h5><a href="https://wpmonks.com/downloads/material-design/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Material Design</a></h5>
+							<h6>Implement Material design on your form with single click.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/bootstrap-icon.png'; ?>">
+							<h5><a href="https://wpmonks.com/downloads/gravity-forms-bootstrap-addon/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Bootstrap</a></h5>
+							<h6>Implement Bootstrap design on your form with single click.</h6>
+						</div>
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/field-icons.png'; ?>">
+							<h5><a href="http://wpmonks.com/downloads/field-icons/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Field Icons</a></h5>
+							<h6>Add image or fontawesome icons to form fields and position them.</h6>
+						</div>
+						<div class="stla-wel-right-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/tooltip.png'; ?>">
+							<h5><a href="http://wpmonks.com/downloads/tooltips/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Tooltip</a></h5>
+							<h6>Add helpful tips for each form field with a wide range of tooltip icon selection</h6>
+						</div>
+						<div class="stla-wel-left-cont stla-wel-feature-box">
+							<img src="<?php echo esc_url( GF_STLA_URL ) . '/css/images/welcome/cs-theme.png'; ?>">
+							<h5><a href="http://wpmonks.com/downloads/custom-themes/?utm_source=dashboard&utm_medium=welcome&utm_campaign=styles_layout_plugin" target="_blank">Custom Themes</a></h5>
+							<h6>Save your current form theme design and implement it on other forms in one click.</h6>
+						</div>
+					</div>
+				</div>
+
+				<div class="stla-wel-addon-feature stla-wel-padding-container">
+					<div class="stla-update-left">
+						<h2> Addon Bundle</h2>
+						<ul>
+							<li><span class="dashicons dashicons-yes"></span> Material Design </li>
+							<li><span class="dashicons dashicons-yes"></span> Bootstrap </li>
+							<li><span class="dashicons dashicons-yes"></span> Theme Pack </li>
+							<li><span class="dashicons dashicons-yes"></span> Tooltips </li>
+							<li><span class="dashicons dashicons-yes"></span> Field Icons </li>
+							<li><span class="dashicons dashicons-yes"></span> Custom Themes </li>
+							<li><span class="dashi

Frequently Asked Questions

Atomic Edge WAF security layer inspecting website traffic.

How Atomic Edge Works

Simple Setup. Powerful Security.

Atomic Edge acts as a security layer between your website & the internet. Our AI inspection and analysis engine auto blocks threats before traditional firewall services can inspect, research and build archaic regex filters.

Get Started

Trusted by Developers & Organizations

Trusted by Developers
Black & McDonald logo representing Enterprise tier security and support for Atomic Edge WAF.Covenant House Toronto logo featuring a dove and text for Atomic Edge Enterprise planAlzheimer Society Canada logo representing trusted organizations and security partners.University of Toronto logo representing trusted organizations using Atomic Edge WAFSpecsavvers logo, trusted developers and organizations using Atomic Edge securityHarvard Medical School logo representing trusted organizations using Atomic Edge WAF.