Changelog

Release Notes

Every feature, every improvement, every fix since v1.0.0.

Page 17 of 20 — 576 releases, newest first.

v2.16.30

Publisher Catalog & Backlink Opportunities, Verified for 2026

  • The Backlink Opportunities module now lists real, verified programs — every niche grew from a couple of search shortcuts to 10-19 named opportunities checked live in 2026: Source of Sources and the relaunched free HARO, unlinked-mention reclamation, Lonely Planet Correspondents, BoardingArea, Matador Creators, foodgawker, mindbodygreen, the Plutus Awards, CryptoPanic, BlogPaws, Google/Bing/Apple business listings and more — each with priority, effort, and a concrete first step.
  • The News Publishers catalog was re-verified for 2026 — Apple News (ANF, four countries), Flipboard (program closed; magazine + bookmarklet path documented), SmartNews and NewsBreak requirements updated; Bundle and SQUID added as open application channels; Pocket and Yandex Dzen removed.
v2.16.29

Brand Consistency, robots.txt Compliance & Full Turkish Admin

  • The Turkish admin is now fully Turkish — dozens of hardcoded English labels were localized across the post editor (Recipe/LocalBusiness schema fields), backups schedule, comment replies, duplicate finder, media upload, banner manager, theme customizer, user profiles and the traffic plugin menu (now "Hızlı İndeksleme", "Anında Bildirim", "RSS Beslemesi", "Backlink Fırsatları", "Tarayıcı Bildirimi"). The English admin remains fully English.
  • robots.txt now passes Bing validation — the non-standard Host: directive (a legacy Yandex extension that Bing flags as an error) was removed from the generated robots.txt on every site.
  • The brand reads "jekcms" everywhere — a repo-wide sweep replaced every wrong-case variant across emails, feeds, installer screens, API docs, theme metadata, user-agent strings and comments. License-key format and code identifiers are untouched, so nothing breaks.
v2.16.28

Proper-Noun Anchors in Internal Linking

  • Auto internal linking now recognises single-word proper nouns — place, brand and topic names such as a city or a dish (capitalised, 5+ letters) can now become link anchors, not just multi-word phrases. Lowercase generic words stay excluded, so the links remain relevant. This noticeably improves internal linking on niche sites (travel, food, local guides) where titles are often a single proper noun.
  • Fixed the content-import wizard showing the "External authority links" label in English on a Turkish admin (it now follows the admin UI language).
v2.16.27

Smarter Internal Linking & E-E-A-T Outbound Links

  • External authority links in the content generator — the content-queue import wizard can now request a set number (0–5) of in-content outbound links to high-authority, non-competitor sources. When enabled, the AI prompt weaves them naturally into the body on descriptive anchors (never a "Sources" list), strengthening E-E-A-T.
  • Auto internal linking now waits for a real library — on a brand-new site there is nothing useful to link to, so auto-linking stays dormant until a configurable minimum number of published posts exists. The Auto Linker screen explains the threshold and shows current progress. As before, only published posts are link targets — queued/scheduled content is never linked.
v2.16.26

Pinterest Production Setup Instructions

  • Clearer Pinterest go-live instructions — after Pinterest grants Standard access, the setup guide now tells you to remove the existing connection and connect again in Production mode, instead of using plain Reconnect (which can silently stay in Sandbox).
v2.16.25

Admin Customer Detail Fix

  • The customer detail screen in the admin panel opens reliably again — orders, licenses, invoices, support tickets and internal notes loaded with queries that did not match the production database, so the page returned a server error. Every section now reads the live schema correctly, and the customer create/edit forms save address details to the right fields.
v2.16.24

Clearer Product Positioning Copy

  • jekcms is now described the same way everywhere — a next-gen smart CMS that installs on any PHP + MySQL hosting. The vague "self-hosted" label (which could read as if hosting were included) and the inaccurate "plugin-free" label were removed from the homepage, the WordPress-alternative page, site metadata and structured data.
v2.16.23

Category Archive Filter Fix

  • Category pages now show only their own posts — on themes that query archives by category ID, the post list ignored the category filter and showed every published post. The core query layer now accepts both category ID and slug, so every category archive lists exactly the posts that belong to it.
v2.16.22

Invoicing, Customer Portal Language & Support System

  • Real PDF invoices — admins can now generate an invoice for any order and email it to the customer, and customers can download a proper PDF from their portal. Invoices render with full Turkish characters and work on any shared host (no server extensions required).
  • Turkish-law VAT handling — domestic sales carry 20% VAT (KDV); sales to customers outside Turkey are treated as a VAT-exempt service export and the exemption note is printed on the invoice automatically.
  • Company billing settings — a new admin screen for your seller details (company title, tax office, tax number, address, IBAN) that appear on every generated invoice.
  • Billing profile for customers — buyers can now enter their tax number, address and country so their invoices are complete and the correct VAT rule is applied.
  • Customer portal fully bilingual — every page of the customer portal (orders, licenses, invoices, support, profile, sign-in/up) now follows the selected language, so Turkish users no longer see stray English labels.
  • Support tickets hardened — fixed an issue where a second ticket from a customer could fail, added missing attachment storage, corrected priority handling, and customers now get an email when staff reply (and staff get one on new tickets).
  • Portal pages that referenced old data fields now load correctly — order detail, new-ticket and invoice pages were updated to the live data model.
  • Two admin tools gained CSRF protection and several blog/theme pages had social-share image and metadata issues corrected for better SEO.
v2.16.21

Automatic Internal Links on Publish

  • New posts get internal links automatically when published — the moment a post goes live (manual publish, scheduled date, or content queue), 3-5 contextual links to your existing published posts are added inside it, so you no longer have to run the linker site by site. Only published posts are used as link targets; queued or scheduled items are never linked.
v2.16.20

Security Hardening Pass: Payment, CSRF, Uploads, SSRF, API

  • Marketing homepage hardening guard aligned — the direct-access guard in the constants file only accepted one context flag, while the marketing site and update-server bootstrap use different ones; the guard now matches the loader so the public site renders normally
  • Payment webhook is now fail-closed — the iyzico webhook now rejects any unsigned or invalid-signature event (matching the Stripe gateway) before an order can be marked paid
  • CSRF enforcement extended to GET admin actions — central CSRF enforcement now also covers authenticated GET action handlers (delete/toggle/activate)
  • API input is column-whitelisted — the categories/tags update endpoints now accept only known fields
  • SVG uploads disabled — SVG is no longer an allowed upload type; standard image formats are unaffected
  • SSRF guards added to server-side fetchers — bulk-import and remote content-image fetching now validate the URL against private/loopback/metadata ranges and no longer follow redirects
  • Customer portal forms fixed — the CSRF token field referenced a non-existent method (so it rendered empty); corrected to the proper token, and a status parameter in pagination links is now URL-encoded
  • Removed a leftover temporary password-reset utility from the web root
v2.16.19

In-Article Images Now Match on Items That Already Have a Pinterest Slot

  • Image matching no longer skips the in-article photos when an item only had a Pinterest slot — after a re-import added a Pinterest slot to an item that had no content image plan, the matcher mistook that lone Pinterest slot for a full plan and never built one from the article's headings, so the cover and pin matched but the in-article images (img02, img03…) stayed in temp. The matcher now ignores the Pinterest slot when deciding whether a content plan exists, builds the heading-based plan when needed, and preserves the existing Pinterest slot
v2.16.18

Re-Importing JSON Now Updates Existing Queue Items (Pinterest + Prompts)

  • Re-importing a JSON now enriches items already in the queue instead of skipping them — previously a duplicate (same source id) was skipped entirely, so content imported before a feature existed could never gain it. Now a re-import fills in any empty image prompts from the new file and adds the Pinterest brief (hook, title, description, tags, image prompt) and pin slot — while preserving already-matched image URLs, the schedule, and any manual edits. The import result reports how many items were updated
v2.16.17

Content Queue Image Column Now Counts the Matched Cover

  • The image-status column no longer shows “—” when the cover is actually matched — items imported without a full image plan store their cover in the featured_image column rather than the plan, so the queue list read “no images” even though the cover thumbnail was clearly set (and the image dialog said “1/1 matched”). The column now counts a column-matched cover too, so the list and the dialog agree
v2.16.16

End-to-End Pinterest Pins: Custom Copy, Per-Category Boards, and Baked Designs

  • Per-article Pinterest copy now publishes — a pin's title and description come from the imported brief (_pinterest_title / _pinterest_description) instead of the generic post title and template, so each pin reads the way it was written
  • Pins route to the matching board automatically — a pin is posted to the board whose name matches the article's category (with the connected account's default board as fallback), so a multi-topic site keeps its Pinterest boards organized with no manual selection
  • Designed-in-full pins are supported — when the image already bakes in its own headline and domain bar, the CMS skips its own stamp (stamp:false), so there is never a double bar
  • The AI content wizard now writes premium pin briefs — when Pinterest is enabled, it produces an editorial brief (short hook, ≤100-char title, ≤500-char keyword-rich caption, tags, the <slug>-pinterest filename, and a full split-layout image prompt with the site domain baked in) ready for image generation
v2.16.15

Hands-Off Pinterest Pins and Bulk Image Matching in the Content Queue

  • Pinterest pins now match automatically — drop a <slug>-pinterest.jpg into the uploads temp folder alongside your article images and the queue picks it up on the next “Match Images” run, stamps your site’s domain bar onto it, and attaches it to the post. No more uploading pins one at a time
  • Pinterest captions travel with the content — the import schema now carries a pin hook (the headline on the image), a meta description (the caption shown under the pin) and tags, and writes them to the published post so a Pinterest publisher can fill those fields without guesswork
  • An image-status column in the queue list — every row shows how many article images are matched (e.g. 2/3) and whether a Pinterest pin is present and matched, at a glance
  • The content queue list was redesigned — the action buttons (view, images, publish, delete) are now a compact, single-row icon group instead of a stack that overflowed the column, and the new image-status chips are monochrome and uncluttered
  • Image matching now shows a real progress bar — a clean progress window reports matched count, percentage and a live log as it processes the temp folder in batches, instead of a number ticking in a button
  • Content Studio is now the calm starting point for publishing — the dashboard gathers the publishing calendar, queue health, next action and entry points for AI draft, planned batches and content packs into one compact two-language screen
  • Imports are more forgiving — image entries that use role/prompt instead of slot/image_prompt are now understood, so content generated by different tools imports correctly without hand-editing the JSON
v2.16.14

Admin Sessions No Longer Drop After a Few Hours Idle

  • You stay signed in until you actually sign out — even with the session cookie and garbage-collection lifetimes already raised to 30 days, an inactivity check was still destroying the session after ~2 hours of no activity (its threshold constant was undefined, so it fell back to a 2-hour default). The idle limit now matches the 30-day session lifetime, so leaving the dashboard open and coming back hours later keeps you logged in
v2.16.13

Admin Language Consistency — Plugin Text Now Follows TR/EN

  • The newer plugins no longer leak the wrong language in the admin — Google Console, Traffic & Distribution, and parts of Social Publishing hardcoded their interface text in a single language (mostly Turkish), so it showed Turkish in the English admin (and vice-versa). All of these are now bilingual and follow the admin language setting
  • Google Console’s plugin-list description is now bilingual — it was missing from the localized description map and fell back to the Turkish manifest text
  • The Two-Factor Authentication card in Settings → Security is now bilingual — its labels, steps, badges and buttons were Turkish-only
  • Social Publishing platform help/how-to, cost and warning texts are now bilingual for all platforms — these registry strings rendered in a single language regardless of admin locale
v2.16.12

Performance (N+1) and Security/SEO/Plugin Hardening

  • List pages issue far fewer database queries — loading a post list with relations ran 6 queries per post (author, categories, tags, meta, SEO, comments); a 12-post page hit ~72 queries. It now batches all of them into 6 total via IN() lookups
  • Image dimension lookups no longer scan the media table on every render — the per-image width/height query used a leading-wildcard LIKE (full-table scan per image); it now uses exact-path matching plus a per-request cache
  • Saving a post no longer wipes the entire object cache — cache invalidation is now targeted to the affected namespaces instead of a global flush
  • Faster LCP on article pages — the hero/featured image on travel and health single-post templates now carries fetchpriority="high"
  • Client IP detection is now trustworthy for blocking — forwarded headers are accepted only when they carry a public IP, so the address used for IP blocking is reliable
  • Redirect Manager blocks dangerous redirect schemes — javascript:/data:/vbscript: targets are refused at emit time
  • Admin error messages no longer leak internals — Security Center and Redirect Manager now show a generic message and log the detail
  • Cross-domain Sitemap line removed from the shipped robots.txt fallback — robots is served dynamically with the site’s own domain; the static fallback no longer carries a hardcoded foreign domain
  • Google Console snippets can no longer double-inject — the head injector is guarded against firing on both head hooks
  • Removed the misleading dead Pinterest-template dropdown in Social Publishing settings (it was never read)
v2.16.11

Deep Audit Fixes — CSRF Enforcement, Cache, SEO & Systems

  • CSRF protection is now enforced centrally across the admin — validation blocks state-changing authenticated requests centrally (clean 419, JSON for AJAX) without affecting public forms or page rendering
  • "Clear Cache" buttons work again — they called a method that did not exist and fataled (purging nothing). Added the missing prefix-delete method and hardened the handler
  • Sitemap index no longer miscounts pages as posts — the posts-sitemap presence/lastmod now filter on post type, fixing false "empty posts sitemap" and wrong freshness signals
  • Update manifest hash guard now fully active — the signed update manifest exposes the core package hash under the field the client checks
  • Social Publishing "Hold for approval" no longer silently stops publishing — held items now appear in the queue with one-click Approve / Approve-All / Cancel actions
  • Traffic & Distribution now verifies TLS — IndexNow/WebSub/Web-Push calls now enforce certificate verification
v2.16.9

Security Center Now Matches the Admin Design System

  • The Security Center looked disconnected from the rest of the admin — it shipped its own stylesheet with hardcoded light-mode colors (white cards, grey borders) instead of the admin’s shared design tokens, so it ignored dark mode and its tabs/cards/tables didn’t match the other panels. Every color now uses the admin theme variables, so it adapts to dark/light and looks like one consistent product. Status indicators keep a subtle tinted badge instead of solid blocks, and the brand wordmark was corrected to lowercase
v2.16.8

Strip Byte-Order Marks From Core Files — Fixes Admin Layout & AJAX

  • Admin pages no longer render with broken styling — several core PHP files (bootstrap, constants, helpers, theme functions) carried an invisible UTF-8 byte-order mark (BOM) before their opening tag. That BOM was emitted before the document’s doctype, which forced browsers into "quirks mode" and broke list/table layouts across the admin. The BOM has been stripped from every PHP file across every installation
  • AJAX actions no longer fail with a JSON parse error — the same BOM was prepended to JSON responses (e.g. "Match Images"), so the browser threw Unexpected token … is not valid JSON. With the BOM removed, responses are clean JSON again
v2.16.7

Match Images — Build Article Image Plans From Your Generated Files

  • Bulk image matching now actually imports your files — the media importer used PHP’s upload-only move function, which always fails for files already on the server (e.g. images you place in the uploads/temp folder). A server-side "sideload" path now imports those files correctly, and a valid uploader id is always supplied so the database insert no longer fails outside a browser session
  • "Match Images" understands multi-image articles — drop files named {slug}-img01..04 in the temp folder and the matcher attaches them as the article’s image plan: image 01 becomes the featured image and the rest are placed in the body after the article’s headings. When the article already has a plan, empty slots are filled in order
  • Admin thumbnails resolve relative image paths — queue list and calendar previews now prefix the uploads URL for plan images stored as relative paths, so the thumbnail shows instead of a broken image
v2.16.6

Match Images — In-Memory Matching, Seconds Instead of Minutes

  • "Match Images" now finishes in seconds on large queues — the previous version ran two full-table LIKE '%slug%' scans per item and re-normalized every media filename for every item, which on a queue of hundreds against thousands of media files took minutes and hit a server gateway timeout (the generic "server error"). The media library is now normalized once and all items are matched in memory — no per-item database queries, no repeated work
v2.16.5

Match Images No Longer Times Out on Large Queues

  • "Match Images" no longer fails with a generic server error on large queues — with hundreds of queued items and thousands of media files, the slug-to-media scan could exceed PHP’s execution limit and return a raw 500. It now skips items that already have an image attached through the image-matching flow (so nothing is re-scanned needlessly), and the time limit is raised for the bulk pass
  • Queue actions now always return a readable error — any failure in a content-queue action is converted to a proper JSON message instead of a raw 500 page, so the browser shows the real reason rather than a generic "server error"
v2.16.4

Reliable Manual Publishing — No More "Spinning then Failed"

  • Publishing no longer crashes when a session cannot start — if output had already begun (e.g. a slow image URL emitting a warning), the session layer threw a fatal "headers already sent" error that aborted the publish even though the post itself was fine. The session now degrades gracefully (logs and continues, fail-closed) instead of crashing background work
  • A dead or slow featured-image URL can’t freeze the publish anymore — image download now has an 8-second connect and 25-second total cap (was 60s with no connect timeout), the single biggest cause of the publish button spinning for up to a minute. A failed download simply falls back to publishing without that image
  • Already-published posts are no longer mislabeled "failed" — if a post was created but a later side-step (cache, session, search-engine ping) errored, the queue now finds the post by slug as well as title and correctly marks it completed
  • The optional in-content image localization can no longer abort a publish — the whole step is now isolated; any error there is skipped and the post still goes live
v2.16.3

Content Queue — Recover Stuck Posts & Fix Missing Thumbnails

  • Scheduled posts can no longer vanish silently — if publishing was interrupted by a fatal error mid-run, the item used to stay frozen in a "processing" state that appeared in no queue tab and was never retried. Publishing now catches every failure type and the auto-publisher reclaims any item stuck longer than 15 minutes, so the backlog clears on the next visit
  • Failed and stuck items are now visible and recoverable — a new "Failed" tab surfaces every problem item (failed or processing) with a one-click retry, instead of leaving them invisible while still showing on the calendar
  • Featured thumbnails show in the admin again — completed posts whose image was attached through the image-matching flow stored the picture in the rich payload, not the legacy column, so the queue list and calendar showed an empty box even though the live post had the image. The admin now reads the matched image as a fallback
  • Calendar hover preview image fixed — the tooltip was building the image path the wrong way around (a local path treated as an external URL and vice-versa), so the preview was always broken. It now uses the same single image resolver as the rest of the queue
v2.16.2

Security Hardening — Per-Install Unique Keys

  • Every installation now generates its own unique security keys — authentication, session and JWT secrets are created with cryptographic randomness on first run and stored outside the distributed package. No two installs share secrets, so a token issued on one site is meaningless on another
  • Install-time integrity manifest — the wizard now signs the tamper-detection manifest with the install’s own key at the end of setup, so a fresh installation never shows a false "integrity" warning
v2.16.1

Migration Polish — Author Links Show Everywhere, Bulletproof .htaccess

  • The installer now guarantees jekcms’ own .htaccess is used — on most WordPress sites the .htaccess is stuffed with SEO/sitemap-plugin rewrite rules that can break clean URLs. The installer detects whether jekcms’ signature is present; if not, it backs the old file up to .htaccess.wp-backup and writes the canonical jekcms .htaccess (read straight from the package, so no drift). Routing is correct even if the host locked the file or the archive lacked it
  • Migrated author social links now actually appear — several themes (Personal, Trends, Lifestyle, Pets, Finance) were reading the old column names and silently showed nothing. They now read the real social_x / social_facebook / social_instagram / social_linkedin / website fields, so the profiles imported in 2.16.0 are visible on author and article pages
v2.16.0

WordPress Migration — Richer, Safer, Cleaner Imports

  • Author profiles now come over in full — biography, website, social links (X, Facebook, Instagram, YouTube, Pinterest, LinkedIn) and a Gravatar-based avatar, instead of just the name. Existing authors are enriched only where fields are empty (never overwritten)
  • Re-running a migration no longer creates duplicates — posts already imported (matched by their original slug) are skipped, so an interrupted migration can be safely resumed
  • Empty categories are cleaned up — WordPress’ default "Uncategorized" and any category with no posts are removed after import, so your category list stays meaningful
  • A clear warning before deleting old files — if you migrated without downloading images (so your content still points at the old site), the cleanup step now warns that deleting the old files would break those images

Go live today

Setup, content management, SEO and image optimization — all in one platform. Get started in 30 minutes.

View Pricing
  • Setup and live in 30 minutes
  • 14 ready-made themes
  • AVIF/WebP image optimization
  • Automatic SEO — Sitemap, Schema.org
  • Cookieless built-in analytics (ZeroTrack)

Be the first to know

New features, release notes & CMS guides — a couple of emails a month, no spam.