Changelog

Release Notes

Every feature, every improvement, every fix since v1.0.0.

Page 15 of 20 — 576 releases, newest first.

v2.21.2

Stories: Consistent Emoji Art, Reaction Switching & Live Reaction Stream

  • Reactions now use embedded SVG emoji art (Twemoji) instead of OS emojis — the same crisp, modern look on every device and browser, with no external requests.
  • You can now change your reaction: tap a different emoji and the previous one is replaced, with counts adjusted correctly behind the scenes.
  • Earlier reactions are now visible to every viewer as a subtle ambient stream — tiny emojis float up the story while it plays, proportional to how many reactions the slide collected.
  • The Statistics page was redesigned: KPI tiles on top, per-slide view bars, CTR column, emoji-by-emoji reaction breakdowns, inline poll result bars, and a visual completion meter per story.
v2.21.1

Instagram-Style Story Reactions

  • Story reactions were redesigned in Instagram's quick-reaction language: six bare emojis (❤️ 😂 😮 😢 🔥 👏) with a springy pop on tap and a shower of emojis floating up the story — no button chrome, no grey chips.
v2.21.0

Stories v1.1 — Auto-Stories, Polls, Reactions & Analytics

  • Auto-stories: when you publish a post, a story is created automatically from its featured image, title, and link — and retires on its own after a configurable lifetime. Your story strip stays fresh with zero manual work.
  • Poll slides: ask a question with 2–4 answers; visitors tap to vote and instantly see live percentage bars. One vote per visitor, no login required.
  • Emoji reactions (🔥 ❤️ 👏) on every slide — a single tap, cookie-free, one reaction per slide, with a satisfying burst animation.
  • Statistics tab: per-slide views with a 7-day column, link clicks with CTR, reactions, poll result breakdowns, and a completion rate showing how many viewers reach the last slide.
v2.20.2

Stories Cache Fix & Cleaner Admin

  • The Stories admin was decluttered: slide editing is now collapsed behind an Edit toggle, add-slide tools are grouped into tidy accordions, and settings use aligned rows with inline inputs.
  • The Stories viewer script is now served with a server-cache bypass, so viewer fixes reach visitors immediately after an update instead of being pinned to a stale cached copy.
  • Closing the viewer is hardened at the style level as well — the close button, Escape, and swipe-down work even if a theme stylesheet interferes.
v2.20.1

Stories Viewer Fixes & Inline Links

  • The story viewer close button (and Escape / swipe-down) now reliably closes the overlay.
  • Slide links are now clickable text instead of a separate button: the caption or card text itself opens the link, and inline links can be placed on any word with [visible text](url) syntax.
  • The story-age indicator in the viewer header now shows explicit units (e.g. "3 h"), so it can no longer be mistaken for the slide duration.
v2.20.0

Stories — Instagram-Style Stories for Your Site

  • New Stories plugin: a tappable story strip with a full-screen viewer — image, video (MP4/WebM), and text-card slides with auto-advancing progress bars, swipe/keyboard navigation, and hold-to-pause. Mobile-first, dependency-free, and zero page weight when no story is live.
  • Every slide can carry a caption, a custom duration, and a call-to-action link with its own label — turn announcements into traffic.
  • Scheduling and auto-expiry: stories go live and retire on their own; permanent "Highlight" stories pin to the end of the strip. View counts are tracked per story, cookie-free.
  • Placement is yours: choose the strip position (below header, top of content, top of page, above footer, or a custom CSS selector) and target pages from settings — saved per theme, works on every theme without touching theme files.
  • Appearance controls with live preview: circle or vertical-card shape, three sizes, classic gradient / solid / no ring, alignment, optional strip heading, and automatic gray rings for already-watched stories.
v2.19.4

License Enforcement Gap-Closing

  • The managed-install marker is now cryptographically signed and bound to its domain. Legitimate managed installs are unaffected.
v2.19.3

License Enforcement & EULA Hardening

  • Licence verification records which distribution a copy came from, so an unauthorised redistribution of a licensed copy can be identified. Legitimate installations are unaffected.
  • The End User License Agreement (EULA) was strengthened with explicit clauses on embedded copy-tracking, its evidentiary value, liquidated damages, and reverse-engineering/rebranding bans; checkout now records EULA acceptance.
v2.19.2

Install Integrity Hardening

  • The install-integrity subsystem was strengthened so unauthorized modification or redistribution of a licensed copy is detected and traceable more reliably. Legitimate installs are unaffected.
v2.19.1

Traffic & Distribution: Web Push Repair, Single IndexNow Key and Outreach Pacing

  • The weekly opportunity limit in the backlink workspace is now actually enforced: once the week's quota is used, new additions are paused with a clear message — keeping outreach deliberate, exactly as the screen promises.
  • Traffic Health now includes a Web Push row: service-worker reachability, subscriber count and the last send at a glance.
  • Web Push now works end-to-end. The public endpoints the browser needs (service worker, key, subscribe) were never wired into the router, so enabling push could not deliver a single notification. They are now first-class routes, subscriptions are validated before being stored, and sending respects a time budget so a large subscriber list can never stall publishing.
  • One IndexNow key per site. The plugin and the core search pinger each generated their own key, leaving two key files in the site root and duplicate submissions. Both layers now share a single key; changing or regenerating it updates everything and removes the stale key file.
  • Saving a setting after a test or an error no longer shows a generic "Saved." — the real result (test outcome, error detail) is now displayed.
  • If VAPID keys could not be generated during activation, Web Push stayed permanently broken with no way to recover; the settings screen now regenerates them automatically and reports failures clearly.
v2.19.0

Social Auto-Publish: Instagram Stories, Discord, Evergreen Re-sharing and Reliability

  • Instagram Stories. Every new post can now also be shared as a 9:16 story a few minutes after the feed post — the image is prepared automatically from the featured image. On by default, one toggle in settings.
  • Discord channel publishing. Zero-friction: paste a channel webhook URL and every new post lands in your community as a rich embed (title, description, image, link). No app registration, no OAuth.
  • Evergreen re-sharing. Opt-in: older evergreen posts are periodically re-shared to your text channels for steady archive traffic — age threshold and daily cap are configurable, visual channels are excluded, and the same post is never repeated within the window.
  • Failed-item recovery. The queue screen now lets you retry or delete failed items (one or all) and shows a 7-day per-platform success-rate table.
  • Adding a new token-based platform no longer requires editing the admin screen: connection forms are generated from the platform registry.
  • Facebook Page connections now exchange for a long-lived token and refresh themselves — previously the token silently died within hours and the account broke on first publish.
  • The queue is now claimed atomically per item, so overlapping schedulers can never double-publish; stuck items self-recover after 30 minutes, and web-cron runs respect a time budget.
  • Pinterest "Diagnose" results were never written to the log (a status value the table did not accept was silently dropped).
  • Expired connections are now labeled as expired with a clear reconnect signal instead of a generic error.
  • The X/Twitter authorization no longer requests a media permission the adapter never uses.
v2.18.34

Admin Raw-Key Repair: 249 Missing Translations Restored

  • Several admin pages showed raw translation keys instead of text (e.g. "admin_blog_posts.th_title") — in both languages. 249 missing dictionary entries were authored in Turkish and English across the blog posts, licenses, email templates, order detail, invoices, backups and login screens; a new linter check now blocks any future use of an undefined key.
  • The theme catalog page and the sidebar's First-Install Package label were hardcoded in Turkish; they now follow the admin language.
  • The invoices screen crashed on load: its overdue-count query referenced a column that never existed (due_at → due_date).
v2.18.33

Customer Portal Fully Bilingual + a Language-Leak Shield

  • A new internal language-leak linter guards every future change: any new user-facing string that is not born as a TR/EN pair is caught before release, so this class of bug cannot silently return.
  • Turkish text no longer leaks into the English customer portal (and vice versa). Every remaining single-language page was made properly bilingual: security settings, email verification, forgot/reset password, checkout and its success/cancel pages, support tickets, downloads and order details.
  • The setup wizard now speaks English. The first screen a new buyer sees was almost entirely Turkish; it is now fully bilingual with a TR/EN switcher, follows the browser language by default, and all of its error messages are translated too.
v2.18.32

Site Name Signal Completed Across every theme

  • Every theme's homepage now marks the site name as an H1 heading — completing all four signals Google documents for choosing the site name shown in search results, so Google stops falling back to the bare domain. The heading renders with zero visual change; inner pages keep their content H1. (Personal shipped in the previous release; the remaining 13 themes are covered now.)
  • The Minimalist theme's header brand was hardcoded to a specific site name; it now follows the Site Name setting like every other theme.
  • The Finance theme showed no brand at all when no logo was uploaded, and its homepage detection could mislabel search or paginated pages; both were corrected.
  • The Recipes theme rendered its brand as an H1 on every page, giving articles two H1s; the brand is an H1 on the homepage only now.
v2.18.31

Personal Theme: Site Name Signal Completed for Google (Homepage H1)

  • Google could fall back to showing your domain instead of your site name in search results. The Personal theme's homepage had no H1 heading — one of the four signals Google documents for choosing a site name (WebSite structured data, og:site_name, title, and a prominent heading). The header brand now renders as an H1 on the homepage only, with identical visual styling; inner pages keep their content H1.
v2.18.30

Buying Goes Live: Pricing-Page Checkout and a Discount Campaign Manager

  • The pricing page now sells. Every plan's button opens the secure checkout with that plan preselected; signed-in customers get their email and name prefilled, and the checkout language follows the site language.
  • Discount campaign manager. Define campaigns in the admin — percentage or fixed amount, date windows, redemption limits, per-plan restrictions and special-day presets (New Year, Black Friday, and more). Campaigns sync to the payment provider automatically; the pricing page shows a campaign banner and can apply the code at checkout without the customer typing anything.
  • Plan prices defined in code had drifted from the public pricing page; they are aligned again.
v2.18.29

International Payments via Polar, Instant License Delivery, and an Account Security Overhaul

  • International card payments via Polar (Merchant of Record). Every paid Polar order automatically creates the customer account, issues the license key, generates the invoice and emails the key — no manual steps. Deliveries are idempotent, webhook signatures are verified, and the checkout thank-you page shows the license key the moment it is ready.
  • Email verification for customer accounts. New registrations receive a verification link (sign-in is never blocked); changing your email re-requires verification of the new address and notifies the old one. A new resend-verification page replaces links that previously led nowhere.
  • Account deletion (GDPR/KVKK). Customers can permanently anonymize their account from the Security page with password confirmation; order and invoice records are retained as required by law.
  • Real login history. The Security page now shows actual sign-in attempts (date, IP, outcome) — the old list was wired to a table nothing ever wrote to.
  • Brute-force protection is now database-backed. The old limiter counted attempts inside the visitor's own session, so clearing cookies reset it; limits are now enforced per email and per IP across sessions, and every attempt is audit-logged.
  • Changing your password now confirms it by email and refreshes the session; the non-functional "Remember me" checkbox was removed (sessions already persist for 30 days).
  • The email verification page queried columns that never existed in production, so verification links could not work; it now uses the real schema.
  • Viewing a support ticket linked to an order could fail due to a query against a non-existent table.
  • Site-validation bots of payment providers were blocked by an over-broad user-agent filter, which made provider onboarding fail with "could not reach this URL".
v2.18.28

Sign-In Flow Streamlined: Session-Aware Header and Google-Only Social Login

  • The site header now recognizes signed-in customers. After signing in or registering, the "Sign In / Get Started" buttons are replaced with "Dashboard" and "Sign Out" — on desktop and in the mobile menu.
  • Signing in no longer pulls you away from the page. Logging in or registering from the site keeps you where you were instead of forcing a redirect to the customer dashboard; Google sign-in returns you to the page you started from.
  • Your language choice follows you into the customer portal. Browsing the site in English opens the dashboard in English after sign-in; browsing in Turkish opens it in Turkish.
  • Social sign-in is now Google only. The rarely used GitHub, Facebook and Microsoft sign-in options were removed from the sign-in modal, the portal pages and the admin settings.
  • Signing out now returns you to the homepage instead of the login screen.
  • Google sign-in errors are now shown. The login page listened for the wrong URL parameter, so OAuth errors (cancelled sign-in, misconfiguration, inactive account) were silently swallowed; all error codes now surface with bilingual messages.
  • The registration modal accepted submissions without the Terms of Service checkbox being ticked; acceptance is now enforced.
  • Sign-in and registration API calls resolved to the wrong path on subfolder installations; they now respect the site base path.
  • Password reset now works on installations missing its table. The password_resets table only existed in a development migration; when absent, the forgot-password form crashed. The table now self-heals on first use, and a mail delivery failure no longer breaks the flow.
  • Login error messages mixed English and Turkish regardless of the chosen portal language; they now follow it.
v2.18.27

Content Tables Are Now Styled in the Personal Theme

  • Tables inside articles now have proper borders, a header row and spacing. The Personal theme had no table styling, so tables rendered as plain unbordered columns that were hard to read. They now have cell borders, a shaded header row, comfortable padding, zebra striping and horizontal scrolling on small screens.
v2.18.26

Schema Gaps Closed for Voting, AI SEO Analysis and IP Blocking

  • Article voting now works. The up/down vote feature (used by the crypto theme) wrote to a post_votes table and a posts.votes column that the schema never created — and an old migration even defined the table with mismatched column names. The table and column are now part of the schema, self-heal on existing sites, and the stale migration was corrected.
  • AI SEO analysis is now saved. The editor's AI analysis wrote to seo_meta columns (ai_score, ai_analysis, ai_analyzed_at) that did not exist, so results were never persisted. The columns were added to the schema and self-heal on existing sites.
  • The IP block list has a proper schema table. Previously it only existed when an admin happened to open the Security Center; it is now part of the core schema and self-heals.
v2.18.25

Schema Consistency: Silent Database Errors Fixed + Drift Guard

  • A schema drift guard now runs in the release pipeline. A new tool cross-checks every table/column written by the code against the schema and plugin definitions; any newly introduced mismatch fails the release, preventing this class of fresh-install error from recurring.
  • Comment replies and API comment creation now save reliably. Both wrote to a column name (ip_address) that did not exist on the comments table (the correct column is author_ip), so these paths failed on every install. They now use the correct column.
  • Automatic IP blocking now actually blocks. The security module wrote a non-existent blocked_at column, so blocks were silently dropped; it now uses the correct column.
  • Theme switching and settings saves are safe on fresh installs. The settings table gained created_at/updated_at columns (added to the schema and self-healed on existing sites) — code wrote these timestamps but the fresh-install schema lacked them.
  • ZeroTrack registers correctly on activation. Its plugin record used the wrong column names (active/core instead of is_active/is_core).
v2.18.24

Log and Data Hygiene: A Self-Limiting CMS

  • Automatic maintenance now covers every accumulating store. Raw view records (180 days), auto-link logs, SEO ping logs and expired Google Console cache entries are pruned on the existing maintenance schedule, and oversized log files (including php-errors.log) are rotated centrally with 30-day cleanup of old rotations.
  • The database error log can no longer grow without bound. It now rotates at 5 MB with a single backup kept, matching the application log. A recurring cron error had been able to grow this file indefinitely.
  • Two chronic error sources were silenced at the root. The webhook queue self-heals missing api_tokens columns on older installs (and the webhook feature starts working), and the AI bulk worker skips quietly when its table is not installed — both had been writing an error entry every minute.
v2.18.23

ZeroTrack: Interactive Trend Chart and Full Localization

  • The trend chart was redesigned from scratch. The bare line chart is now an interactive bar chart: hovering highlights the bar and its neighbors, shows a tooltip with views and unique visitors, and updates the live value in the header. Days with no data render as zero instead of being skipped, and the "Today" range now shows an hourly breakdown.
  • KPI cards now compare against the previous period. Page views, unique visitors and sessions show a rise/fall percentage next to the label.
  • The whole plugin follows the admin design system and language. Every label on the dashboard and settings pages is fully localized (Turkish admin shows Turkish everywhere), and hard-coded light-theme colors were replaced with design tokens so dark mode renders correctly. Top pages gained proportional usage bars.
v2.18.22

Google Console: Consistent Reports and a Permanent-Connection Guide

  • Search Console and Analytics now report the same date window. GA4 requests previously ended "today" while Search Console ended yesterday, so overview KPIs compared different periods. Both now use the identical range, making trends directly comparable.
  • Keyword and page tables show up to 50 rows (previously 20), and indexing-coverage scans now cover up to 2,000 URLs (previously 500) in line with Google's URL Inspection daily quota.
  • Reconnect banner now explains the most common cause. When Google drops the connection with invalid_grant — typically because the OAuth app was left in "Testing" mode, which expires grants after 7 days — the panel says so and walks through publishing the app to production for a permanent connection. The setup guide covers this too.
  • Search Console site addresses are normalized on save. Entering a bare domain becomes a proper domain property (sc-domain:), and URL-prefix properties get their required trailing slash — malformed values used to fail silently with empty reports.
v2.18.21

Newsletter Result Pages Work on Every Theme, in Both Languages

  • Newsletter subscribe/confirm/unsubscribe pages no longer crash on non-Personal themes. These pages called a Personal-theme helper directly, which caused a server error on any other active theme. They now use a theme-safe helper and render their texts in the site language (Turkish or English) instead of hard-coded Turkish.
v2.18.20

Visible Spam Protection, Reliable Newsletter Signup, Consistent Plugin Naming

  • The built-in spam filter is now visible and explainable. The Comments screen links directly to Spam Protection settings, flagged comments show their spam score with the reasons that triggered it, and the spam tab offers a one-click "Not Spam" action. The filter itself (link limits, keyword/IP/e-mail blacklists, submit-speed and repeat-offender checks) was already scoring every comment behind the scenes.
  • Plugin names and ordering are consistent everywhere. The sidebar now uses the same localized plugin names as the Plugins screen, and both lists are sorted alphabetically by the displayed name.
  • Theme customizer is fully localized. Tab and theme descriptions now appear in Turkish on Turkish admin panels, and the page title follows the admin language.
  • Newsletter signup now works from every theme. Several themes posted their subscribe forms to endpoints that did not exist (/newsletter, /api/v1/newsletter/subscribe), so signups silently failed. Both endpoints now reach the newsletter plugin, and the API works in sub-directory installs too.
  • Fresh installs no longer break on comments or subscribers. The installer schema was missing the spam-score columns on comments and the subscribed_at column on newsletter subscribers; both are now in the schema and self-heal on existing sites.
  • New-post notification e-mails render correctly. The notification campaign stored post data as raw JSON that would have been printed into the e-mail; the sender now resolves it into the template placeholders.
  • Crypto theme footer now obeys the customizer. The "Brand blurb" field is actually rendered, the social-icons toggle works, the site name is no longer hard-coded, and the footer subscribe form posts to the correct endpoint.
v2.18.19

Instant Admin Asset Updates, Dropdown Clipping Fix

  • Admin CSS/JS updates now reach the browser immediately. Stylesheet and script URLs are versioned by file modification time instead of the CMS version number, so hotfixes no longer require a hard refresh or a version bump to become visible.
  • Custom dropdown panels are no longer clipped by their card. When a select panel (such as the Author picker in the post editor) is open, its containing card temporarily allows overflow so the full option list is visible.
v2.18.18

Author Picker on the Post Editor, Sentence-Aware Excerpts

  • Posts can now be assigned to a different author from the editor. A new Author dropdown in the Publish box lists the site's writers; the change is saved with the post. Autosave and quick-edit paths are unaffected.
  • Auto-generated excerpts no longer cut off mid-phrase. The generator now prefers the last full sentence within the window, ignores version-number dots (like "GPT-3.5"), is UTF-8 safe for Turkish characters, and inserts spaces where block tags met. Existing truncated excerpts across all sites were regenerated from content.
v2.18.17

Pro Theme Customizer: Font Previews, Import/Export, Turkish UI, Deeper Options

  • Theme settings can now be exported and imported as JSON — move a finished design to another install in one click, with schema-validated import, cross-theme confirmation and a one-click "Reset to defaults" that preserves footer-builder data.
  • Font pickers became real font pickers. A central 38-family library backs every font field (empty dropdowns are gone), the current font sits selected at the top, every option renders in its own typeface, and a live preview line updates as you browse.
  • Deeper per-theme options, all wired to real output: the Personal theme gained homepage controls (hero slide count, popular section and count, categories toggle, posts-per-page for the latest grid) and a Post Page tab (sidebar, author card, related posts and count, comments) — every switch verified to change the rendered page.
  • The customizer speaks Turkish now. Over a hundred remaining English field and tab labels across all theme schemas were translated for Turkish admin sessions.
v2.18.16

Fresh-Install Audit: Theme Switching, Customizer and Setup Hardened End-to-End

  • A full customer-journey audit (installer → theme switching → customizer → import) fixed nine fresh-install bugs. Subdirectory installs no longer hit an infinite redirect on About/legal pages; single-post pages now receive author data, so the News theme no longer crashes; the Tech theme's missing helper, the Finance theme's missing comments partial, and Health theme null-image crashes are all resolved.
  • Search works on every host now. Reusing one SQL placeholder twice broke search with an SQL error on servers where PDO prepares are not emulated — fixed in the core query builder, the Health theme and the quiz plugin.
  • Saving the Theme Customizer no longer wipes other settings. It used to replace the theme's whole customization record, silently deleting footer-builder data; it now updates only its own fields. The footer builder likewise activates only on themes that render it, instead of corrupting other themes' footer settings.
  • Setup polish: application logging now creates its log directory on first use (it was silently dead on fresh installs), broken absolute-path ErrorDocument rules were removed, and session ini warnings on first requests are gone.

Go live today

Setup, content management, SEO and image optimization — all in one platform. Get started in 30 minutes.

View Pricing
  • Setup and live in 30 minutes
  • 14 ready-made themes
  • AVIF/WebP image optimization
  • Automatic SEO — Sitemap, Schema.org
  • Cookieless built-in analytics (ZeroTrack)

Be the first to know

New features, release notes & CMS guides — a couple of emails a month, no spam.