Description
At a glance
Looking for FonX Delete User v1.1.0? It is available here as a free GPL download for WordPress — updated September 24, 2026 · requires WordPress 6.7+ & PHP 8.2+.
FonX Delete User turns account erasure into a controlled, reviewed process instead of a one-click auto-delete.
Most “delete my account” plugins force visitors into their own button or form. FonX Delete User takes the opposite approach: you keep the form you already have and the plugin quietly powers it in whichever way fits your site.
What makes it different
- Bring-your-own-form — integrate any existing HTML form on your site with a CSS selector and data-fxldu-field mapping. The form you styled stays the form your visitors see; the plugin’s JavaScript attaches to it without blocking its own handler.
- Config-only mode — toggle the plugin’s own markup off entirely. The shortcode or block still emits the per-site request token and configuration, so an existing form can drive submissions with nothing extra rendered.
- Admin approval pipeline — nothing is deleted automatically. Every request waits in the admin queue for you to approve, reject, or delete it.
- External API mode — instead of deleting inside WordPress, forward erasure submissions to your own endpoint for the external system to complete.
- Audit logging — every request and outcome is recorded in the database or a file, with a built-in viewer.
Features
- Dual deletion modes — store requests pending admin approval (wordpress_db) or forward submissions immediately to an external endpoint (external_api).
- Form builder — add text, email, password, textarea, checkbox, select, and hidden fields with required toggles, placeholders, options, and validation regexes.
- Flexible injection — the [fxldu_form] shortcode, a native Gutenberg block, or integration with an existing page form via CSS selector and data-* field mapping.
- Email notifications — alert the administrator (or a custom admin email) about new requests, and acknowledge the requester by email with configurable subject/body and placeholders.
- Security hardening — honeypot anti-bot field, per-site HMAC-compatible request tokens, per-IP rate limiting, capability-gated admin endpoints, prepared SQL, and fully escaped output.
Submission flow
- A visitor submits the form (shortcode, block, or an integrated existing form).
- The frontend checks the honeypot, validates required fields, and posts a JSON request containing a per-site token, the user email, and the collected fields.
- The request is stored with status pending (rate-limited per IP).
- The administrator is notified; the requester can also receive an acknowledgement email.
- On approval, the user is permanently deleted via wp_delete_user() (WordPress Database mode) or the request is marked approved for the external system (External API mode). On rejection, the request is marked rejected and no deletion happens.
- The requester is notified of the outcome.
Additional Information
This release addresses the points raised during the plugin review and hardens two runtime paths found while testing. Details of what changed and why:
- Global prefix — every global identifier now uses the unique
fxlduprefix instead of the genericdu_/delete_user_names: option keys, database tables, transients, the REST namespace (fxldu/v1), action/filter names, nonces, admin menu slugs, the[fxldu_form]shortcode, thefxldu/formblock, enqueue handles, JavaScript globals, and frontend CSS classes. PHP constants areFXLDU_*and the class namespace isFxldu. The text domainfonx-delete-userand the plugin folder name are unchanged. - Database cleanup — the admin list tables (Fields, Requests, Logs) and the REST listing endpoint no longer pass an empty argument list to
$wpdb->prepare()when no filter or search is applied; in that case the static count query runs directly instead of emitting the “the query argument must have a placeholder” notice. - Existing-form integration — when the integration selector matches a non-form container (some themes wrap their form in a div that is matched instead of the
<form>itself), field collection and email resolution now read the named inputs directly instead of throwing insidenew FormData(). The window integration-guard is__fxlduIntegrationBound. - Script output — the frontend form configuration is no longer printed as raw inline
<script>tags. The shortcode and block register thefxldu-frontendscript throughwp_enqueue_script()and inject the config object withwp_add_inline_script( 'fxldu-frontend', $js, 'before' ). The unusedprint_frontend_config()method was removed from the main plugin file, and no<script>or<style>strings remain in the plugin source. - Sanitization of custom headers — the admin live-test of the API connection now passes the custom headers through
sanitize_textarea_field( wp_unslash( $_POST['api_headers'] ) )before building the request, matching the sanitization applied when the headers are saved. - Contributors — the
Contributors:header now uses the plugin owner’s WordPress.org username. - Log file location — file logging no longer writes to a hard-coded
WP_CONTENT_DIRpath. Logs now go to a plugin-specific subfolder under the uploads directory ({uploads}/fxldu/fxldu-logs.log), created withwp_mkdir_p(), and each line is appended witherror_log( $line, 3, $log_path ). - External-request REST proxy — the
/external-requestroute remains open for anonymous form submissions but is now hardened: it keeps the honeypot check and the per-site token verification, strips internal keys from the forwarded payload, fails closed with HTTP 403 unless External API mode is active, and is rate-limited per IP (its own transient counter so a normal submission still counts only once per endpoint leg). - Uninstall cleanup — the broad
option_name LIKEquery (which could delete options owned by other plugins sharing the old prefix) and a usermetaLIKEcleanup (the plugin writes no user meta) were removed.uninstall.phpnow deletes an explicit list of the 26 options owned by this plugin plus the three plugin-owned database tables. - Rate-limit filter — the
fxldu_rate_limitfilter documented in the FAQ is now actually applied. Both the/requestand/external-requestendpoints enforce their per-IP limit through a shared helper whose default ismax( 1, Options::get_rate_limit() )and which honorsapply_filters( 'fxldu_rate_limit', $limit, $ip ).
Frequently asked questions
What is FonX Delete User?
FonX Delete User is a free WordPress plugin available under the GPL license. The current version is 1.1.0.
Is FonX Delete User free to download?
Yes — FonX Delete User 1.1.0 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.
How do I install FonX Delete User 1.1.0?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for FonX Delete User?
FonX Delete User 1.1.0 requires WordPress 6.7 or higher and PHP 8.2 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was FonX Delete User last updated?
Version 1.1.0 was last updated on September 24, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the FonX Delete User download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 1.1.0 |
|---|---|
| Last updated | September 24, 2026 |
| Requires WordPress | 6.7 or higher |
| Requires PHP | 8.2 or higher |
| Author | Tabi Idris |
| Tags | account-deletion, delete-user, form-builder, gdpr, user-management |
Download FonX Delete User
Download FonX Delete User WP PluginNote: if the download does not start, disable your ad blocker and try again.