Changelog
What changed in the WP Octo application, by date. Newest first.
The application is updated for everyone at once, so what matters is the day a change reached you. Each entry names the part of the product it is in.
17-09-2026
- Improved – plugins and themes: Each plugin or theme appears once in the lists, however many sites carry it; duplicate entries have been merged with their sites, versions and advisories kept
- Improved – security: A vulnerability check that cannot judge one advisory continues with the rest, and the drawer says why a version is not checked instead of leaving it blank
- Improved – plugins and themes: A website's own Plugins and Themes pages show the same risk, version and status columns as the workspace lists, with their actions kept
- Added – plugins and themes: A plugin or theme whose author has not released anything in twelve months carries a label and a notice
- Improved – plugins and themes: The Info tab shows a component's description in full, and the drawer's tabs no longer shift after the first click
- Added – website overview: A website opens with its health score, the time of the last check, one row per aspect that is measured, and a list of what needs attention
- Improved – dashboard: Fleet health on the workspace dashboard is shown as the average health score of the checked sites
- Fixed – navigation: The active menu item has its marker and highlight back
16-09-2026
- Added – plugins and themes: One row per plugin or theme, with a drawer holding its vulnerabilities, information, changelog, sites and versions, a risk badge per row, icons, and a Vulnerable only filter
- Added – websites: A website's own Plugins and Themes pages open the same drawer, every website has an Activity page, and the Reports page carries the website header
- Added – navigation: Control Center is a navigation tree under Websites, and a website's pages open with the main menu collapsed
- Fixed – plugins and themes: Plugins are recognised by their folder, so information and vulnerability lookups resolve for components that were previously unmatched
15-09-2026
- Fixed – updates: An update round in a state the dashboard does not recognise is shown as an unknown status in the activity feed and on the Update Rounds pages instead of an error
14-09-2026
- Fixed – security: Vulnerability checks store their results again, and the plugin and theme lists show status, severity and the version that fixes an advisory
- Fixed – websites: The websites list summary and the fleet summary labels no longer overflow their space
13-09-2026
- Added – security: Plugins, themes and core versions across the fleet are checked against known vulnerabilities
- Security – updates: The bulk Run update round action is hidden from members without the permission to run update rounds
- Security – access: The Websites and Update Rounds lists are confined to the current workspace explicitly
- Fixed – subscriptions: The subscription lists skip a plan they cannot render instead of failing
- Fixed – websites: The website Settings header no longer overlaps its actions on desktop
- Fixed – announcements: An announcement no longer appears before its place on the page exists, and one dismissed from its close button stays dismissed
- Fixed – updates: The update-round chart draws in the panel's colours, and its link applies the completion filter it names
- Improved – plugins and themes: Plugin and theme icons sit on a surface that follows light and dark mode
12-09-2026
- Fixed – dashboard: On a phone the dashboard widgets no longer stay on loading or overlap the website header
- Added – websites: A site's thumbnail condition is readable in the panel, as a list column, a badge in the site header and a fleet metric for thumbnail issues
- Improved – updates: An update round that stalls is closed as abandoned and shown as such, instead of staying open indefinitely
08-09-2026
- Improved – backups: A backup completes on a site whose host blocks WP Octo's calls, and is far lighter on the site while it runs
- Improved – backups: A backup that is due starts promptly on a site WP Octo can reach, rather than waiting for the site's next scheduled task
- Improved – health: A site that reports as expected is no longer shown as stale between two of its reports
- Improved – worker updates: A site WP Octo could not reach during a worker update still receives the release through WordPress's own updates, and is recorded as updated once it has
- Fixed – worker updates: A site WP Octo could not reach for a worker update is recorded as unreachable rather than as failed
- Fixed – connection: A site whose host allows WP Octo, as its Health page instructs, is no longer reported as blocked by a firewall
07-09-2026
- Added – backups: Scheduled backups from the package with a per-site override, storage policies for the site, object storage or both, and restore from the external copy
- Added – backups: A central Backups page; Restore is offered only where a restore point exists, and the storage choice is limited to what the workspace has
- Improved – backups: The backup list is checked against what is actually on the site and in storage, so a backup whose copies are gone is no longer offered for a restore
- Improved – backups: A backup found on the site or in storage that WP Octo did not know about is verified in full before it is offered for a restore
- Added – health: A site WP Octo cannot reach is shown with the cause — DNS, certificate, timeout, a firewall with the provider named, plugin inactive, authentication failed — is checked again on its own, and receives the worker release it missed once it is reachable again
- Improved – health: A site blocked by its host's firewall shows on its Health page what to allow and where
- Added – sync: A site keeps WP Octo up to date on its own, so a host firewall no longer leaves its plugins, themes, users, core, health and backups stale, and every site shows when its data was last received
- Added – connection: A site running a JWT authentication plugin connects to WP Octo once its worker is current; that plugin used to stand in the way
- Improved – updates: A plugin update the site refused for a permanent reason, such as a missing licence, is not retried, and the reason is recorded
- Improved – roles: A member with the client role is read-only and can no longer log in to a site through the dashboard
- Security – access: A client member is limited to the sites of the clients they are attached to everywhere, the API included
- Fixed – sync: A site with many backups no longer fails its first report to WP Octo
06-09-2026
- Fixed – sign in: The login page refused every password; signing in with a password works again
- Fixed – updates: A plugin update the site refused is recorded as refused rather than as a success the site then disagreed with
- Improved – regression: The regression results table loads in a fraction of the time and shows its screenshots in one view
03-09-2026
- Improved – dashboard: Every screen follows the light or dark theme
- Improved – updates: The outcome of a plugin update is verified against the site rather than taken from the site's own report
- Security – access: The workspace API key is no longer visible to a read-only role