PluginProbe
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions / 260927
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions v260927
260927 260917 260913 260909 260829 260814 260805 110710 110731 110812 110815 110912 110913 110915 110926 110927 111002 111003 111011 111017 111029 111105 111206 111216 111220 All 190 releases
s2member / readme.txt

readme.txt in s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions 260927, at readme.txt

975 lines 97.0 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 === s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions ===
2
3 Plugin Name: s2Member Framework
4 Plugin URI: https://s2member.com/
5 Tags: membership, content restriction, paid subscriptions, members only, paid access
6 Version: 260927
7 Stable tag: 260927
8 Tested up to: 7.2-alpha-63947
9 Requires at least: 4.2
10 Requires PHP: 5.6.2
11 Tested up to PHP: 8.5.9
12 License: GNU General Public License v2 or later.
13 Contributors: WebSharks, JasWSInc, raamdev, clavaque, eduan
14 Author: s2Member
15 Author URI: https://s2member.com/
16 Donate link: https://s2member.com/donate/
17 Beta link: https://s2member.com/beta-testers/
18 Forum URI: https://s2member.com/r/forum/
19 Privacy URI: https://s2member.com/privacy-policy/
20 Changelog URI: https://s2member.com/changelog/
21 Video Tutorials: https://s2member.com/r/s2member-videos/
22 Knowledge Base: https://s2member.com/kb/
23 More Updates: https://s2member.com/category/news-updates/
24 Newsletter: https://s2member.com/r/subscribe/
25 PayPal Pro Integration: https://s2member.com/r/pp-account-types/
26 Text Domain: s2member
27 Domain Path: /languages
28
29 ❤️ Excellent membership plugin! Easy, quick, flexible. Monetize your site with memberships and subscriptions. Protect content instantly and securely.
30
31 == Description ==
32
33 ❤️ **Excellent membership plugin!** Over 15 years of experience, development, releases... Still going and growing!
34
35 **Start your membership profits!** Build your tribe, gather your followers, enroll your students, bring in your clients!
36
37 💵 Enjoy the benefits of getting paid repeatedly for access to your site!
38
39 ⭐⭐⭐⭐⭐ _**Brilliant** "So glad I found this. It works brilliantly for our needs... love the seamless integration with PayPal. Everything we need. Thank you so much for creating this!" -[zarverk2000](https://wordpress.org/support/topic/brilliant-1268/)_
40
41 = The best way to make money from your WordPress site! =
42
43 🤩 Sell **unlimited memberships**, turn free subscribers into members (_subscriber to member → s. 2 member → s2Member_), with a single payment or recurring payments subscriptions.
44
45 **Easy and quick to use.** Protect your membership content in a moment, and a moment later be ready to get payments for member access!
46
47 **Easy to configure and very flexible.** Protect the whole site, nothing, or just parts, even member files for paid downloads!
48
49 👉 Install s2Member now and **make money!** 😀
50
51 https://youtu.be/qlKn-I-0W6U
52
53 ⭐⭐⭐⭐⭐ _**So much capacity & great support** "I’m a novice and was able to quickly figure it out. When I got stuck I go to the support forum and Cristian is there with a quick answer to get me going again." -[blueruck](https://wordpress.org/support/topic/so-much-capacity-great-support/)_
54
55 ⭐⭐⭐⭐⭐ _**The very best plugin and support service** "Great plugin, neat, easy to configure, and with interesting security features. A special mention to Cristian whose support is awesome, fast, clear even to free members like myself" -[aflorarte](https://wordpress.org/support/topic/the-very-best-plugin-and-support-service/)_
56
57 **Packed with features**, but not required to use them all, just those you want. Some of them:
58
59 ➡️ Member user levels and custom access capabilities
60 ➡️ Membership content protection (post, page, category, tag, etc)
61 ➡️ Protect anything served by WP (post types, URLs)
62 ➡️ Member file protection (sell downloads)
63 ➡️ Prevent member account sharing (limit IPs, simultaneous logins)
64 ➡️ Protect accounts (limit failed login attempts)
65 ➡️ Cool security/trust badge with your domain
66 ➡️ PayPal Standard buttons for membership payments (more in Pro)
67 ➡️ Automatic member access demotion at end of paid access time
68 ➡️ Tracking software integration (affiliates, etc)
69 ➡️ Email list services (Mailchimp, etc)
70 ➡️ Notifications (signups, payments, etc)
71 ➡️ Integrate with bbPress, BuddyPress for member communities
72 ➡️ Compatible with any well coded theme (Elementor, Divi, etc)
73 ➡️ Customize the WP login/registration look
74 ➡️ Custom redirection after member login
75 ➡️ Create custom profile fields for member accounts
76 ➡️ Customize the user welcome email
77 ➡️ And more!
78
79 👉 Install and start using s2Member now! 🤩
80
81 ⭐⭐⭐⭐⭐ _**Very Powerful Membership Plugin** "This membership plugin does a lot and has many, many configuration options to achieve whatever you want... I received extremely quick and reliable support." -[liltrucks](https://wordpress.org/support/topic/very-powerful-membership-plugin/)_
82
83 ⭐⭐⭐⭐⭐ _**Simple, Compatible, Secure, and Versatile!** "We are seriously impressed with this plugin and we highly recommend it... We have not found ANY limitations to what we are trying to accomplish... a very smooth process... straight-forward and user-friendly!... exceeded our expectations!" -[tips4gamers](https://wordpress.org/support/topic/simple-compatible-secure-and-versatile/)_
84
85 ⭐⭐⭐⭐⭐ _**Excellent plugin** "This plugin does everything it says on the box. It does it well... the functionality is absolutely spot on. The developers/maintainers are also active and helpful. Totally recommended!" -[richardfoley](https://wordpress.org/support/topic/excellent-plugin-5188/)_
86
87 ⭐⭐⭐⭐⭐ _**Best Membership Plugin I’ve Used** "I switched to s2 Member around 3 years ago after trying a few plugins. I found these other plugins inflexible and difficult to configure... Well worth investigating if you want a robust membership solution." -[rnwhalley](https://wordpress.org/support/topic/best-membership-plugin-ive-used/)_
88
89 🤖 Not needed to know any PHP code or be a developer. Only code needed is copy-paste wp shortcodes, like for the paypal buttons... But is also developer-friendly to customize your installation if wanted.
90
91 = Some reasons to get s2Member Pro =
92
93 �
94 Membership content dripping
95 �
96 Stripe, PayPal Pro, Authorize.Net, ClickBank
97 �
98 On-site one-step checkout with pro-forms (Stripe, PayPal, Auth.Net)
99 �
100 Unlimited membership levels
101 �
102 Membership renewal reminder emails
103 �
104 Single-step member registration and payment with pro-forms
105 �
106 Custom redirection after payment
107 �
108 Coupon codes and gift/redemption codes
109 �
110 Custom member offer redirections after login
111 �
112 Pro API for new integrations
113 �
114 Public members directory
115 �
116 Members bulk import/update/exporter
117 �
118 Multisite network support
119 �
120 Login and registration forms to use in pages/posts
121 👉 [Click here for more](https://s2member.com/features/) 🙂
122
123 ⭐⭐⭐⭐⭐ _**The Best Membership Plugin** "I have built with most Membership plugins and literally dozens using S2 Pro and I can tell you, bar none it is the best of all of them. Extremely powerful, anything you might want to do it can do... I highly recommend you try it out." -[antwoords](https://wordpress.org/support/topic/the-best-membership-plugin-5/)_
124
125 ⭐⭐⭐⭐⭐ _**Excellent plugin & top support** "We’ve used s2member pro on a few projects now & find it has met all our membership needs. Most impressive has been the support. Excellent communication, knowledgeable, friendly and super patient 🙂" -[aaee6](https://wordpress.org/support/topic/excellent-plugin-top-support-3/)_
126
127 ⭐⭐⭐⭐⭐ _**Awesome Support** "I’ve been using s2Member for 9 years... Amazing support of a high-end plugin and much appreciated. This is one of the reasons I stick with s2Member. Support has always been great!" -[graphichome](https://wordpress.org/support/topic/awesome-support-712/)_
128
129 ⭐⭐⭐⭐⭐ _**Wonderful Support** "Above and beyond. I’ve used this plugin for over ten years with various clients and whenever I need help, they’ve helped find a solution." -[germars](https://wordpress.org/support/topic/wonderful-support-68/)_
130
131 The free s2Member Framework integrates with PayPal Website Payments Standard (also free). Sell "Buy Now" or Membership access to your site. Restrict access to Roles, Capabilities, Posts, Pages, or anything else in WordPress.
132
133 Protect your WordPress Posts, Pages, Tags, Categories, URIs, BuddyPress, bbPress, and even portions of content within Posts, Pages, themes, plugins. **Easily configurable and highly extensible.** You can even protect downloadable files and streaming audio/video. Store files locally, or use s2Member's integration with Amazon S3/CloudFront.
134
135 s2Member is powered almost entirely by WordPress shortcodes, making advanced integrations quick and easy. Sell recurring (or non-recurring) subscriptions with lots of flexibility. Or sell "Buy Now" membership access in various ways. You can also sell specific Posts/Pages, sell member access to file downloads, or sell members Custom Capabilities that provide highly configurable access to specific portions of your content.
136
137 👉 Install now s2Member and **start making money!** 😀
138
139 == Installation ==
140
141 **NOTICE:** For help with s2Member Pro, please use [our forum](http://s2member.com/r/forum/).
142
143 = s2Member is very easy to install =
144
145 Just like any other normal plugin:
146
147 - From the WP Admin's [Plugins Add New Screen](https://wordpress.org/support/article/plugins-add-new-screen/).
148 - Or via FTP upload the `s2member` folder from the zip to your `/wp-content/plugins/` directory.
149 - Activate it from **Plugins** page in your WordPress Admin.
150
151 Here's a [quick-start video](https://www.youtube.com/watch?v=qlKn-I-0W6U) for a simple basic setup to get you started.
152
153 = See also =
154
155 [Detailed installation/upgrade instructions](http://s2member.com/installation/).
156
157 = Is s2Member compatible with Multisite Networking? =
158
159 Yes, requires s2Member Pro for Unlimited Sites. After you enable Multisite Networking, with s2Member Framework and Pro active, navigate to `s2Member → Multisite (Config)` in the Dashboard on your Main Site.
160
161 == Screenshots ==
162
163 1. s2Member Screenshot #1
164 2. s2Member Screenshot #2
165 3. s2Member Screenshot #3
166 4. s2Member Screenshot #4
167 5. s2Member Screenshot #5
168 6. s2Member Screenshot #6
169 7. s2Member Screenshot #7
170
171 == Frequently Asked Questions ==
172
173 **NOTICE:** For help with s2Member Pro, please use [our forum](http://s2member.com/r/forum/).
174
175 = Is s2Member compatible with Multisite Networking? =
176
177 Yes, s2Member Pro for Unlimited Sites is compatible with Multisite Networking. After you enable Multisite Networking, with s2Member Framework and Pro enabled, navigate to `s2Member → Multisite (Config)` in the Dashboard on your Main Site.
178
179 = Where can I find more information? =
180
181 * s2Member FAQs: <http://s2member.com/faqs/>
182 * Knowledge Base: <http://s2member.com/kb/>
183 * Video Tutorials: <http://s2member.com/videos/>
184 * Community: <http://s2member.com/r/forum/>
185 * Codex: <http://s2member.com/codex/>
186
187 = Translating s2Member =
188
189 Please see: <http://s2member.com/r/translations/>
190
191 == Upgrade Notice ==
192
193 = v260927 =
194
195 (SECURITY RELEASE) UPGRADE IMMEDIATELY. v260215 included a CRITICAL VULNERABILITY fix, and you shouldn't wait any longer to update if you're behind.
196
197 == Changelog ==
198
199 = v260927 =
200
201 - (Pro) **Fix:** Improved Stripe 3D Secure recovery when browser and webhook processing overlap, or when the browser loses the final checkout response after successful authentication. s2Member now reconciles those recovery paths using the saved checkout state so successful signups can finish correctly without repeating fulfillment. Thanks to Felix for reporting it. See [thread #13627](https://f.wpsharks.com/t/13627).
202
203 - (Framework) **Fix:** Improved Gateway Checkout state handling so concurrent recovery paths can safely patch independent checkout data and explicitly reload newly committed state without stale request-local cache values.
204
205 - (Pro) **Fix:** Improved Stripe subscription recovery for new customers when payment authentication continues after the initial Pro-Form request. s2Member now keeps the pending WordPress account linked to the checkout, allowing browser or webhook recovery to complete the correct signup without losing its account association.
206
207 - (Pro) **Fix:** In a rare Stripe pending-payment recovery case, membership processing could already be complete while the original checkout request still saw an older cached copy of the member's data and continued showing a processing state. s2Member now refreshes that data before deciding whether fulfillment has completed.
208
209 - (Pro) **Fix:** Stripe one-time (Buy Now) Pro-Form purchases requiring 3D Secure could lose the password entered during the initial checkout when the form resumed after authentication. s2Member now keeps the same pending WordPress account through authentication and completes it with the password the customer originally chose.
210
211 - (Pro) **Fix:** Closed a remaining failed-3D-Secure cleanup case where Stripe.js could return an authentication error without the PaymentIntent details used by s2Member's cleanup flow. s2Member now recovers the PaymentIntent ID from the existing Stripe client secret when needed so the incomplete subscription can still be cleaned up correctly.
212
213 - (Pro) **Fix:** Failed card authentication during Stripe free-trial subscription checkout could leave the pending subscription active in a trialing state at Stripe. s2Member now cancels the incomplete subscription generation so unsuccessful authentication attempts do not leave orphaned trial subscriptions behind.
214
215 - (Pro) **Fix:** Immediately retrying a Stripe free-trial subscription with another card after failed authentication could overlap with cleanup of the previous attempt or fail to continue correctly. s2Member now safely finishes that cleanup, confirms the retried authentication when needed, and starts a fresh subscription attempt without browser and webhook recovery interfering with each other.
216
217 - (Pro) **Compatibility:** Improved Stripe SDK loading so s2Member does not accidentally trigger another plugin's dormant Stripe autoloader. This prevents an older Stripe library registered by another plugin from loading before s2Member Pro's bundled Stripe SDK.
218
219 - (Pro) **Fix:** Prevented a PHP warning during Stripe Buy Now checkouts for existing members when determining whether a previous recurring subscription should be cancelled.
220
221 - (Framework) **Compatibility:** Expanded no-cache support for caching solutions that use their own page-exclusion APIs or signals in addition to the commonly supported WordPress no-cache conventions. Added explicit compatibility for LiteSpeed Cache, FlyingPress, Super Page Cache for Cloudflare, WP Fastest Cache, and Cloudflare APO, helping prevent dynamic/private s2Member pages from being cached.
222
223 - (Pro) **Fix:** When `[s2Member-List]` used `rlc_satisfy="ANY"` with multiple Levels, Roles, or Custom Capabilities, additional filtering on the member list could cause unrelated members to appear. Membership filters are now grouped correctly, so only members matching the requested criteria are returned. Thanks to Philip for reporting this.
224
225 - (Framework) **Fix:** PayPal IPN domain checks could fail on some server setups when the incoming request did not provide a usable domain, for example with some reverse-proxy setups where something like Nginx, Cloudflare, a load balancer, etc. sits in front of WordPress and affects the request host. s2Member now falls back to the site's configured domain when needed.
226
227 - (Framework) **Fix:** Some unexpected PayPal proxy values could cause notifications to fail and be ignored. These values are now normalized before the notification is processed.
228
229 - (Framework) **Fix:** PayPal proxy notifications could fail on sites where their domain differs from the site's configured domain. s2Member now uses the appropriate site domain more consistently in these cases.
230
231 - (Framework) **Fix:** Corrected the timeout value passed to the Mailchimp API client, preventing an invalid HTTP stream configuration that could interfere with list subscription requests.
232
233 - (Framework) **Fix:** Avoided calling WordPress's deprecated `force_ssl_login()` helper on current WordPress versions when determining login and RPC URL schemes, preventing deprecation notices while preserving the same SSL behavior and compatibility with older WordPress versions.
234
235 - (Framework) **Fix:** Prevented PHP notices from the `[s2Member-Security-Badge /]` shortcode when the optional `v` attribute is omitted. The shortcode now applies its default badge version before validating the value.
236
237 - (Framework) **Fix:** Prevented PHP notices from the `[s2Stream /]` shortcode when the optional `player` attribute is omitted. Existing player defaults and behavior are unchanged.
238
239 - (Framework & Pro) **UI:** Shortcode whitelist security notices are now more compact and easier to review, grouping detected user fields and template paths instead of repeating each shortcode occurrence, and listing the affected pages once with direct links. Thanks to Sherry for her feedback on these. _WP Admin > s2Member > General Options > Shortcode User Fields Whitelist_ and _Pro Shortcode Templates Whitelist_
240
241 - (Framework) **UI:** Corrected several PayPal Button Generator shortcode attribute descriptions to match current PayPal Checkout behavior, particularly the `output` and `image` attributes.
242
243 = v260917 =
244
245 - (Framework) **Performance:** Further improved searching on the _WP Admin > Users_ screen, building on the performance improvements introduced in v260909. Searches across user profiles and s2Member membership data now require substantially less database work, with the biggest benefit on sites with large member databases. This can make member administration noticeably faster while preserving the same searchable fields, sorting, and pagination.
246
247 - (Pro) **Performance:** Significantly improved `[s2Member-List]` and `[s2Member-List-Search]` performance for member directories and searches, especially on sites with larger user databases. Member searches now require substantially less database work, with much more efficient profile-field searching, filtering, sorting, and pagination. This can make large member directories noticeably faster and more responsive while preserving the shortcodes' existing Custom Field, wildcard, filtering, pagination, and sorting features. See: [s2Member-List Shortcode Documentation](https://s2member.com/kb-article/s2member-list-shortcode-documentation/).
248
249 - (Framework) **Performance:** Improved Alternative View Protection performance on sites with larger amounts of protected content. Searches, archives, menus, widgets, and other areas where restricted content needs to be filtered now do less repeated work during each page request, helping busy pages load more efficiently while preserving the same access-control behavior. _WP Admin > s2Member > Alternative View Protection_
250
251 - (Pro) **Performance:** Reduced overhead when End-of-Term reminder emails are disabled. The heavier reminder processing, health, and email code is now loaded only when it is actually needed.
252
253 - (Framework & Pro) **Security & UI:** Added a prominent admin warning for outdated s2Member Pro installations that predate the current Pro updater. The Framework now warns administrators when an old Pro version may be missing recent security fixes, shows how old the installed release is, and provides a prominent link to download the latest Pro version. The warning does not disable the installed Pro add-on or its features.
254
255 - (Pro) **Security:** Enforced the _Shortcode User Fields Whitelist_ for `[s2Member-List]`'s `show_fields` attribute. Fields not on the whitelist are now omitted from Member Lists, with an administrator notice identifying blocked fields that may need to be allowed. _WP Admin > s2Member > General Options > Shortcode User Fields Whitelist_
256
257 - (Pro) **Security:** Enforced the _Pro Shortcode Templates Whitelist_. Custom templates specified with the `template` attribute are now blocked unless specifically allowed. The shortcode uses its standard template instead, and an administrator notice identifies blocked template files that may need to be allowed. _WP Admin > s2Member > General Options > Pro Shortcode Templates Whitelist_
258
259 - (Pro) **Improvement:** Hardened validation of PayPal Pro-Form `success` URLs used after subscription cancellation. Redirects are now limited to normal HTTP(S) destinations after replacement codes are processed, preventing executable or other non-web URL schemes from being used. Also hardened malformed programmatic `success` values to avoid PHP warnings.
260
261 - (Framework) **Fix & UI:** Corrected Asset Health reporting when static CSS or JavaScript cannot be used because the site's current hooks or configuration require dynamic delivery. This intentional compatibility behavior is now treated as healthy instead of being reported as an unexpected fallback, and it no longer creates misleading "Latest Issues" entries. Asset Health now identifies why dynamic delivery is required, explains when the Full WordPress Dynamic Loader is necessary, and points to the "JavaScript Text Delivery" setting when it can help more pages continue using static JavaScript.
262
263 - (Framework) **Improvement:** EOT demotion traditionally replaced all of a member's WordPress roles, but some sites need to preserve unrelated roles. The new _Demote From_ setting can now remove only the member's s2Member Level role instead. New installations use this level-only behavior by default; existing installations keep the legacy replace-all behavior unless changed. Thanks to Craig for suggesting this. See: [thread #13494](https://f.wpsharks.com/t/13494).
264
265 - (Framework) **Improvement:** EOT demotion normally sends members to _Subscriber / s2Member Level 0_, and using another role previously required custom code. The new _Demote To Role_ setting lets site owners choose another s2Member Level or an available custom role directly from the EOT settings. Existing customizations using the `ws_plugin__s2member_force_demotion_role` filter continue to work.
266
267 - (Pro) **Improvement:** PayPal Checkout cancellation buttons using `output="button"` can now also use a `success=""` attribute to redirect the member after a successful subscription cancellation. If no Success URL is provided, the existing cancellation confirmation remains unchanged. Thanks to Felix for suggesting this. See: [thread #13462](https://f.wpsharks.com/t/13462/7)
268
269 - (Framework) **Improvement:** Added date formatting support to the `[s2Get /]` shortcode when retrieving the current user's registration timestamps. `S2MEMBER_CURRENT_USER_REGISTRATION_TIME` and `S2MEMBER_CURRENT_USER_PAID_REGISTRATION_TIME` can now use the existing `date_format` attribute (e.g., `m/d/Y`, `default`, or `timestamp`), making these timestamps easier to display as readable dates without custom PHP. Also corrected the related scripting documentation to distinguish registration day counts from Unix timestamps. Thanks to Gerard for suggesting this. See [thread #13221](https://f.wpsharks.com/t/13221).
270
271 - (Framework) **Improvement:** Expanded the AWS S3 region selector with several compatible regions that were missing: Canada Central (`ca-central-1`), Ohio (`us-east-2`), Mumbai (`ap-south-1`), Paris (`eu-west-3`), and Stockholm (`eu-north-1`). Sites using buckets in those regions can now select them directly. Thanks to David for the reminder. See: [thread #4706](https://f.wpsharks.com/t/4706).
272
273 - (Framework & Pro) **Improvement:** Added some needed filters that were missing, giving developers more ways to customize s2Member emails and Tracking Codes.
274
275 - (Pro) **Fix:** Resolved PHP 8.x warnings in `[s2Member-List]` caused by optional member-query arguments, including `meta_query`, not always being present.
276
277 - (Framework) **Fix:** Prevented a fatal error in the s2Member-Only dynamic CSS/JS loader when BuddyPress is detected but its `bp_is_create_blog()` helper is unavailable. This also prevents affected sites from unnecessarily falling back to the Full WordPress Dynamic asset loader.
278
279 = v260913 =
280
281 - (Framework) **Fix:** Made frontend CSS/JavaScript monitoring less impatient on sites where expected assets take a little longer to become active. Although the monitor already waited until the page had fully loaded before checking, some setups make their CSS/JavaScript become active a little later, which could cause a false alarm. This has now been fixed. Thanks to Gerard for reporting this. See: [thread #13609](https://f.wpsharks.com/t/13609)
282
283 - (Framework) **Enhancement:** Expanded the frontend CSS/JavaScript monitoring introduced in the previous release into a new "CSS/JS Asset Health" system. The earlier monitoring layer is now smarter, more patient, more informative, more self-healing, quieter when the administrator does not need to intervene, and still designed to stay lightweight during normal frontend traffic.
284 - **New overall health status:** "CSS/JS Asset Health" monitors frontend assets, including the Pro add-on's assets when installed, keeps track of recent delivery results, and summarizes the current situation as "Healthy", "Recent issue", "Working, review suggested", or "Needs attention" instead of reacting to every individual hiccup in isolation.
285 - **More patient, configurable checks:** The original monitor checked whether expected assets had become active 1 second after the page finished loading. The default wait is now 3 seconds, and the new "Wait Before Checking Frontend Assets" setting lets site owners adjust that delay for setups where optimization, caching, networking, or other conditions make assets become active a little later.
286 - **Smarter issue handling:** A single delayed or uncertain result no longer needs to become an immediate administrator problem. Asset Health considers both how recent and how persistent problems are, and can return to "Healthy" as normal loads continue.
287 - **More resilient automatic recovery:** If an enabled static asset file unexpectedly disappears, s2Member will try to rebuild it automatically the moment the problem is encountered instead of waiting for the administrator to refresh it manually. Assets that need rebuilding can also be recovered during normal admin activity, avoiding an extra rebuild during a frontend page-load when possible, and relevant settings changes can trigger affected assets to be rebuilt immediately, too.
288 - **Clearer diagnostics:** The new Asset Health panel shows each CSS/JavaScript asset and its current delivery state, including "Healthy", "Late", "Fallback", "Failed", "Not generated yet", and "Pending rebuild", with plain-language details when more information is useful. A persistent "Last issue" reminder and compact "Latest Issues" log preserve useful troubleshooting details, including affected frontend URLs, occurrence times, and repeated occurrences, with controls to clear them when they are no longer useful.
289 - **Fallback visibility:** Asset Health understands s2Member's existing automatic fallback behavior, distinguishes successful delivery from successful fallback, and shows when the preferred delivery method could not be used but a compatible fallback kept the asset working. It can also show when the fallback itself is unavailable, even while the preferred delivery method is still working, so the administrator knows that the safety net needs attention before it's needed.
290 - **More useful administrator notices:** Short-lived issues are given time to recover without unnecessary warnings. When a problem persists long enough to deserve attention, or is serious enough to require attention sooner, s2Member can show a compact administrator notice explaining the affected asset and link directly to the "CSS/JS Asset Health" section for review.
291 - **Manual recovery and rechecking:** The "Refresh Static Assets" button rebuilds the enabled static files, while the "Recheck Asset Health" button performs a fresh check of the current delivery setup. Refreshing static assets also rechecks their health automatically afterward.
292 - **Performance-conscious health tracking:** Frontend page-loads save small, independent Asset Health records without waiting for the shared health history to be updated. Those events are merged into the rolling history separately and in chronological order, preserving delayed reports and recent-issue details without making normal frontend page-loads wait on Asset Health bookkeeping.
293
294 - (Framework) **UI:** Refined the CSS/JavaScript delivery controls and status presentation. Renamed the beta section to "CSS/JS Delivery & Optimization (Beta)", improved the shared health-status colors used across s2Member status sections, clarified help text and status explanations, and corrected the disabled "Refresh Static Assets" button so it remains visibly disabled when unavailable because static assets are not enabled or a configuration change needs to be saved first.
295
296 - (Framework) **Fix:** Corrected a compatibility issue that could cause a PHP fatal error when another plugin printed WordPress scripts unusually early, before s2Member had finished initializing. s2Member now handles that early script output safely. Thanks to Sim Architect for reporting it.
297
298 - (Pro) **Improvement:** EOT Reminder failure notices are now more actionable. Reminder Status can identify the oldest failing recipient and, when available, the related WordPress user. Persistent admin warnings can now be dismissed for the current incident, while retry and failure details remain available in the _EOT Reminder Status_ section. A materially new or escalated critical reminder problem will alert administrators again. Thanks to Matt for reporting this.
299
300 - (Framework & Pro) **Fix:** Restored compatibility with WordPress 4.2–4.3 by replacing uses of `wp_parse_url()`, which wasn't introduced until WordPress 4.4.
301
302 = v260909 =
303
304 - (Framework & Pro) **Major Improvement:** Until now, s2Member normally generated CSS/JS assets dynamically because some of their contents can change depending on the visitor or other conditions. Dynamic generation requires PHP and WordPress to load before each file can be built. s2Member can now build in advance the parts that don't change and whose contents are shared across all visitors, and save them as static files, allowing the web server to return them directly without loading WordPress for each request. In our tests, static requests were consistently more than 100× faster than dynamic delivery, helping pages load faster while reducing server work. See _WP Admin > s2Member > General Options > Performance & Caching > Static CSS/JS Optimization (beta)_.
305 - **Flexible opt-in controls:** Enable static CSS, static JavaScript, or both. The existing _CSS/JS Lazy Loading_ option still controls which pages load s2Member's files.
306 - **Better caching for logged-in users:** Most of s2Member's JavaScript is the same for everyone, so it can now be shared and cached instead of being rebuilt separately for each visitor. Personal/member-specific values stay with the WordPress page and are never stored in reusable static files. This lets logged-in and logged-out visitors reuse the same shared JavaScript more effectively across page views.
307 - **Pro and gateway support:** Pro core and enabled-gateway CSS and JavaScript can use the same static delivery, combining, and minification options.
308 - **Flexible static asset delivery:** Static Framework and Pro assets can be kept separate for more granular caching, refreshing, and monitoring, or combined into one CSS file and one JavaScript file to minimize the number of requests.
309 - **Optional automatic minification:** Generated CSS and JavaScript can also be minified automatically. Smaller files take less time and bandwidth to download, helping pages load faster, especially on slower connections.
310 - **Multilingual-site optimization:** Sites that change language between pages or visitors can reuse the same static JavaScript file across languages. s2Member loads translated messages and other page-varying values with each WordPress page instead, while personal/member details always remain page-specific and are never stored in reusable static files. Single-language sites can keep more site-wide values in the static JavaScript file for maximum efficiency.
311 - **Reliable automatic fallback:** Static delivery is an optimization, not a requirement for the site to keep working. If a static file cannot be used, rebuilt, or delivered correctly, s2Member automatically falls back to a compatible dynamic delivery method instead of serving a stale or broken asset.
312 - **Targeted refreshes and recovery:** When relevant settings change, s2Member refreshes only the affected static files. During normal WordPress admin use, s2Member also checks that active generated files are still available and working. If a problem is confirmed, it can fall back safely, show an administrator warning, and provide a Refresh Static Assets control to recreate the files.
313 - **Troubleshooting and event logging:** When s2Member logging is enabled, a dedicated `css-js.log` records important CSS/JavaScript delivery events such as generation and refreshes, configuration changes, loader or delivery problems, automatic fallbacks and recoveries, browser-reported runtime issues, and stale-file cleanup, without logging routine page loads.
314 - **Safer plugin updates:** s2Member keeps its generated static JavaScript synchronized with the installed Framework and Pro versions. If an older generated file no longer matches the current plugin files, s2Member rebuilds it or falls back safely instead of risking broken JavaScript after an update.
315 - **Cache-safe cleanup:** Recently replaced static files are kept temporarily so visitors can still load pages cached with an older file URL. Older unused generations are cleaned up automatically, preventing the generated-assets directory from growing indefinitely.
316
317 - (Framework & Pro) **Improvement:** Added a choice of loaders for dynamically generated CSS and JavaScript. The Lightweight s2Member Loader remains the default and avoids loading more of WordPress than necessary for better performance. A WordPress Loader option is also available, loading WordPress normally for these asset requests on sites where the server or security software blocks direct s2member-o.php requests. Configure it from _WP Admin > s2Member > General Options > Performance & Caching > Dynamic CSS/JS Loader_. See [Mod Security (Odd 403, 503, 500 Errors)](https://s2member.com/kb-article/mod-security-odd-403-503-500-errors/)
318
319 - (Framework & Pro) **Fix:** Due to an earlier change in WordPress, s2Member's dynamic CSS and JavaScript loader could end up loading more of WordPress than necessary, making those files slower to load. Its original lightweight loading behavior has now been restored. See: [s2Member-Only Mode](https://s2member.com/kb-article/s2member-only-mode/)
320
321 - (Framework) **Improvement:** Added a shared checkout recovery system that lets supported gateways preserve an in-progress checkout across requests, prevent overlapping processing, and recognize a checkout that already completed even if the browser lost the final response. Recovery information can be retained securely for up to 7 days by default, providing a common foundation for safer retry and recovery behavior across payment gateways.
322
323 - (Pro) **Improvement:** PayPal Checkout Pro-Forms now keep a durable checkout identity across reloads, back/forward navigation, and interrupted browser requests. This gives s2Member a reliable way to reconnect the customer with the same PayPal checkout already in progress, while remaining compatible with older in-progress recovery state during the transition.
324
325 - (Pro) **Security:** Hardened password handling across Pro-Forms as part of the new checkout recovery protections. Submitted passwords are not carried into reusable PayPal Checkout recovery state or repopulated if the form has to be shown again after submission. If an interrupted checkout is later recovered without the original browser session, WordPress's secure set-password flow is used instead.
326
327 - (Pro) **Security:** Hardened Specific Post/Page checkout recovery by minimizing the form data saved for interrupted-checkout recovery. Sensitive payment fields are explicitly excluded from saved recovery state, adding an extra safeguard against unexpected checkout data being retained.
328
329 - (Pro) **Fix:** Significantly extended Stripe Pro-Form duplicate-billing protection for interrupted or retried checkouts. If a reload, interrupted request, lost response, or 3D Secure retry leaves an existing Stripe payment or subscription in progress, s2Member now preserves enough checkout state to find and resume that same payment or subscription instead of accidentally starting another one. This extends the duplicate-charge protection added in v260829 to several additional failure and recovery paths. See [thread 13589](https://f.wpsharks.com/t/13589).
330
331 - (Pro) **Fix:** Improved handling when a successful Stripe Pro-Form checkout completes on the server but the final confirmation never reaches the customer. Because the form can still appear unfinished, the customer may submit it again even though Stripe already completed the payment. Successful checkout results are now retained server-side so s2Member can recognize the completed checkout and resume from the saved result instead of treating the retry as a new payment attempt.
332
333 - (Pro) **Fix:** Strengthened duplicate-subscription protection in PayPal Checkout Pro-Forms. Subscriptions are now created server-side and recorded before browser approval continues, so reloads, lost PayPal responses, interrupted callbacks, and retries can recover and reuse the subscription already created at PayPal instead of creating another one.
334
335 - (Pro) **Fix:** Corrected PayPal Checkout subscription activation handling so membership access is not granted while PayPal still considers the subscription pending approval. s2Member now waits for PayPal to confirm activation, and can recover that confirmation through PayPal's webhook if the browser response is lost or delayed.
336
337 - (Pro) **Fix:** Added comprehensive recovery for interrupted or delayed PayPal Checkout one-time payments. s2Member now keeps track of both the PayPal order and its payment capture, safely handles lost or ambiguous responses, keeps access pending until PayPal confirms the payment completed, and can later recover a completed payment through either the browser or PayPal's webhook without attempting a second capture. The recovery state is also kept deliberately minimal without retaining sensitive checkout data.
338
339 - (Framework) **Performance:** Reduced overhead in high-frequency query and capability checks by bypassing hook and filter setup when nothing is registered and avoiding unnecessary construction of hook context variables, while preserving registered callbacks and WordPress `all` hook compatibility. Screens and operations that perform many capability checks, such as the WordPress Users list, can benefit especially from these savings.
340
341 - (Framework) **Performance:** Reduced database overhead during page loads by eliminating repeated access-restriction database queries within the same request, reusing the initial lookup result.
342
343 - (Pro) **Improvement:** The Pro updater now handles version mismatches more clearly when the latest Pro release is ahead of the installed Framework. It recommends updating the Framework first, or links to the [Release Archive](https://s2member.com/release-archive/) for a matching Pro version when staying on the current Framework.
344
345 - (Pro) **Performance:** Moved checks for available Pro updates to a background task. The latest available Pro version is now saved locally and reused for up to a day when deciding whether to show the Pro Updater. This way, slow Pro availability checks or connection problems can't delay frontend or admin page loads. After Framework updates, a fresh background check keeps compatibility information current.
346
347 - (Pro) **Performance:** Moved the Pro server environment details collection to a background task, so it can't delay normal admin page loads.
348
349 - (Pro) **Performance:** Eliminated repeated cron and transient housekeeping during normal page loads when End-of-Term reminders are disabled, moving the necessary cleanup to settings changes and stale background callbacks.
350
351 - (Framework) **Improvement:** End-of-Term Administrative Notes in the user's profile now use the level custom names when the "Force WordPress to use your Labels" setting is enabled. Also, if a user is already in the configured demotion role, the note now says so instead of recording a "role change" to the same role.
352
353 - (Framework) **Fix:** Solved a remaining PayPal cancellation EOT issue when stored IPN Signup Vars are completely missing. An older subscription check could prevent the newer PayPal lookup from running, causing the EOT to fall back to an incorrect one-day period. s2Member now uses PayPal's next billing date when available. Thanks to Felix for reporting this. See [thread 13462](https://f.wpsharks.com/t/13462).
354
355 - (Framework) **Fix:** Improved Automatic End-of-Term health warnings on low-traffic sites. A delayed WP-Cron event, which can happen when there have been few or no site visitors to trigger it, is now shown as an Attention item without triggering the admin warning by itself, while missing cron or an actual overdue EOT backlog still triggers the stronger warning. EOT warning links also now open the relevant settings panel and jump directly to the affected setting.
356
357 - (Framework) **Fix:** Prevented PHP warnings during some Stripe cancellation/End-of-Term processing when currency information is missing. s2Member now recovers the stored payment currency when possible, and continues processing cleanly without PHP warnings.
358
359 - (Framework) **Fix:** In some edge cases, legacy encryption/decryption could trigger a PHP 8.5 deprecation warning for certain byte values. The byte handling is now explicitly normalized while preserving compatibility with existing encrypted data.
360
361 - (Framework) **Fix:** Redacting sensitive data in large multiline gateway/API logs could cause the regular-expression redaction step to fail and trigger PHP 8.1+ deprecation warnings. Redaction now handles large log entries more reliably.
362
363 - (Framework) **Fix:** The bundled Mailchimp API client could trigger a PHP 8.1+ deprecation warning by passing a deprecated `null` value during query-string construction. It now uses the correct empty-string value instead, preserving the same API request behavior.
364
365 - (Pro) **Fix:** ClickBank request processing could trigger PHP 8.1+ deprecation warnings by passing a deprecated `null` value during query-string construction. Those calls now use the correct empty-string value instead, preserving the same request behavior.
366
367 - (Framework) **Fix:** PayPal notifications and returns could trigger PHP warnings when the optional `s2member_paypal_proxy` and `s2member_paypal_proxy_use` fields were absent. Those optional fields are now set to empty values when missing before processing, while preserving existing gateway integration behavior.
368
369 - (Pro) **Fix:** Prevented a PHP warning when processing malformed Stripe webhook payloads by validating the decoded event before accessing its ID.
370
371 - (Framework) **Fix:** Corrected an off-by-one issue in Brute Force Login Protection that allowed one additional login attempt after the configured failed-login limit had been reached.
372
373 = v260829 =
374
375 - (Framework) **Major Improvement:** Rebuilt the Automatic End-of-Term processing engine so membership expirations are handled more reliably and promptly when due, even on busy sites or after delays, while making the system safer to administer and easier to review and troubleshoot.
376 - **Faster, adaptive processing:** Instead of stopping after 6 users, the new engine uses the safe processing time available in each run and adapts to current speed, allowing it to handle hundreds of users in one pass.
377 - **Rapid queue catch-up:** s2Member processes each member as promptly as practical after their actual EOT time is reached. If work remains, it continues about a minute later instead of waiting for the next regular 10-minute check. In our stress testing, a 1,000-user queue was processed in under 2 minutes, while the old 6-user limit would take almost 28 hours.
378 - **More resilient processing:** Overlapping runs are prevented, interrupted or stale runs recover cleanly, and unfinished work remains available for the next pass instead of being lost or unnecessarily delayed.
379 - **Safer "Delete" behavior and review:** Automatic Delete now removes membership access and moves the user account to Pending Deletion instead of permanently deleting it, preserving useful payment/subscription details for review before single/bulk deletion. Irreversible automatic deletion can still be enabled with the `ws_plugin__s2member_allow_eot_user_deletion` filter. _WP Admin > Users > Pending Deletion_
380 - **New End-of-Term user lists:** Added separate Current and Previous lists with EOT Time, Last EOT, and EOT Demotion columns. Current shows users with an EOT, earliest first; Previous shows prior EOTs, most recent demotion first. Older demotion times are recovered from Administrative Notes where possible. _WP Admin > Users > End-of-Term Current / End-of-Term Previous_
381 - **Better demotion history:** EOT actions, including moves to Pending Deletion, now leave more useful Administrative Notes with the role change, removed Custom Capabilities, subscription details, and the EOT that triggered the action. For example: _2026-08-31 00:03 EDT s2Member: Demoted from Level 1 to Subscriber (removed ccaps: courses). PayPal I-ABC123. EOT 2026-08-31 00:01 EDT._
382 - **Visible health and automatic recovery:** A new Automatic Behavior Status shows pending and overdue EOTs, recent processing activity, the next scheduled run, and the current processing runtime, making delays and other problems visible instead of silent. s2Member repairs a missing WP-Cron schedule automatically when possible, and alerts administrators when a problem persists and needs attention.
383
384 - (Pro) **Major Improvement:** Rebuilt the End-of-Term Reminder Email processing engine so renewal notices have a better chance of going out promptly on their intended day, even after WP-Cron delays or temporary email sending problems that could previously prevent them from being sent.
385 - **Fast, adaptive processing:** The new engine replaces the old 6-member limit with safe runtime-based processing, prevents overlapping runs, recovers interrupted ones, and continues about a minute later when more work remains. On our test server, 1,000 reminders were handed off through WordPress's mail system in about 42 minutes, while the old engine would need almost 28 hours.
386 - **Independent reminder engine:** Reminders based on stored End-of-Term dates now have their own schedule and processing engine, so they no longer depend on membership-expiration processing completing first and aren't held up by a large or stalled End-of-Term queue.
387 - **Forgiving timing and smart retries:** Reminder eligibility now uses calendar days, giving s2Member opportunities throughout the intended send day plus an extra recovery day in case of delays. Failed sends are retried after about 10 minutes, 30 minutes, 1 hour, and then every 3 hours while still eligible, with each recipient tracked independently to avoid duplicate resends.
388 - **Visible health and automatic recovery:** A new End-of-Term Reminder Status shows scheduling activity, recent successful delivery, and recipients currently being retried, with additional failure and recovery details when something goes wrong. s2Member repairs a missing reminder schedule when possible, retries failed recipients automatically, and alerts administrators when problems persist and need attention.
389
390 - (Framework & Pro) **Fix:** Fixed the long-standing issue where the Automatic End-of-Term setting could appear blank when its WP-Cron event was missing. The saved setting now remains visible while s2Member reports and repairs the scheduling problem separately.
391
392 - (Pro) **Fix:** End-of-Term renewal reminders are no longer sent when membership access ended because of a refund, payment reversal, or chargeback. These payment exceptions are now distinguished from normal membership expirations so they don't trigger inappropriate renewal notices.
393
394 - (Pro) **Enhancement:** Modernized s2Member Pro-Forms with PayPal Checkout, using PayPal's current REST APIs and Smart Payment Buttons for off-site payments. When PayPal Checkout is enabled in s2Member, it replaces the legacy PayPal Express Checkout integration for payments completed on PayPal's site. Existing Pro-Form shortcodes work as-is (no edits required). Enable it under _WP Admin > s2Member > PayPal Options > PayPal Checkout (Beta)_.
395
396 - (Framework) **Improvement:** Strengthened PayPal Checkout REST order validation, capture reliability, retry handling, and payment processing safeguards.
397
398 - (Framework) **Improvement:** Better PayPal Checkout button feedback with clearer, more visible error and status messages below the button.
399
400 - (Framework) **Improvement:** Better compatibility for sites using PayPal Checkout while older PayPal subscriptions remain active. Since PayPal subscriptions generally need the integration that created them, s2Member now uses the appropriate one for next payment dates, reminder emails, `[s2EOT]`, and cancellations.
401
402 - (Framework) **Security:** Strengthened PayPal Checkout return validation and payment-flow integrity.
403
404 - (Framework) **Fix:** Improved PayPal Checkout subscription fulfillment retry handling, preventing failed payment notifications from being incorrectly marked complete and allowing browser or webhook recovery to retry safely.
405
406 - (Framework) **Fix:** PayPal Checkout now registers all required webhook events. Existing configured webhooks are updated automatically after upgrading, adding notifications for subscription activation/updates, payment refunds/reversals, and disputes/chargebacks.
407
408 - (Pro) **Fix:** Strengthened Stripe Pro-Forms against duplicate charges from concurrent or repeated submissions of the same rendered checkout. Stripe requests now use a stable per-checkout idempotency ID, simultaneous submissions are blocked while payment processing is in progress, and a failed update to an existing PaymentIntent no longer falls through to creating another one. Thanks to DrCheap for the detailed report and investigation. See [thread 13589](https://f.wpsharks.com/t/13589).
409
410 - (Pro) **Fix:** Fixed a Stripe compatibility issue that could cause `[s2Member-Profile /]` and Stripe billing-update forms to crash when retrieving an existing subscription with newer Stripe API responses/SDK behavior. Thanks to Tim Hibberd for reporting it and providing a patch. See [thread 13575](https://f.wpsharks.com/t/13575).
411
412 - (Pro) **UI:** Updated Stripe Webhook/IPN setup guidance to list all seven events s2Member handles. Sites with an existing Stripe webhook configured for selected events should make sure all seven are selected, including `charge.dispute.created`, so disputes/chargebacks can follow the configured Reversals/Disputes EOT behavior.
413
414 - (Pro) **Improvement:** Added an optional `placeholder` attribute for Authorize.Net, PayPal, and Stripe Pro-Form Checkout Options. This allows a Pro-Form to start with a non-payable prompt instead of automatically selecting the first Checkout Option, requiring the customer to choose a real option before the full checkout form is shown.
415
416 - (Framework & Pro) **Fix:** Improved shortcode attribute handling when editors replace straight quotes with smart/curly quotes. s2Member now also normalizes literal smart quotes so values such as `attribute=“0”` are interpreted correctly. Thanks to Vincent for reporting it. See [thread 13572](https://f.wpsharks.com/t/13572).
417
418 - (Framework) **Enhancement:** Added a hook after profile modifications are saved and s2Member refreshes the user data, allowing integrations to read freshly updated user and custom profile fields. Thanks to Craig for bringing attention to this use case. See [thread 13515](https://f.wpsharks.com/t/13515).
419
420 - (Framework & Pro) **Improvement:** Bumped PHP version compatibility up to PHP 8.5.9 after addressing the remaining deprecation notices and related compatibility issues, while maintaining support for older PHP versions.
421
422 - (Framework) **Fix:** Hardened PayPal recurring-payment handling for missing optional IPN fields and memberships without Custom Capabilities, preventing PHP warnings and deprecation notices.
423
424 - (Framework) **Fix:** Hardened gateway notification and return handlers against missing or null optional transaction fields, preventing PHP warnings and deprecation notices.
425
426 - (Framework) **Fix:** Prevented PHP warnings during registrations or membership updates when optional details (like Custom Capabilities or EOT) weren't used.
427
428 - (Framework) **Fix:** Corrected an edge case in subscription modifications where an optional EOT component could end up in the Custom Capabilities value.
429
430 - (Framework) **Fix:** Fixed PHP 8 compatibility issues in legacy OpenSSL/RSA signing and the Markdown fallback that could fail in some cases.
431
432 = v260814 =
433
434 - (Framework) **Improvement:** Better s2Member Security Encryption Key handling and related guidance in the admin panel.
435
436 - (Framework) **Improvement:** Hardened input validation and sanitization for the `s2Key`, `s2File`, `s2Stream`, and `s2Member-PayPal-Button` shortcodes.
437
438 - (Framework & Pro) **Improvement:** Renamed and expanded the `s2Get` shortcode's user-field whitelist into the shared _Shortcode User Fields Whitelist_ setting, now used for `s2Get`'s `user_id` attribute and `s2Member-List`'s `show_fields` attribute. Administrators are warned when either shortcode attempts to display an un-whitelisted field's value that doesn't belong to the current user viewing the page.
439
440 - (Framework & Pro) **Security:** Improved validation and hardened handling of serialized data throughout s2Member.
441
442 - (Pro) **Improvement:** Hardened input validation and sanitization for the `s2Member-Login`, `s2Member-Summary`, `s2Member-Gift-Codes`, `s2Member-List`, `s2Member-List-Search-Box`, and `s2Member-Pro-ClickBank-Button` shortcodes, as well as the Pro Login Widget.
443
444 - (Pro) **Security:** Added stricter handling for `s2Member-List`'s `show_fields` attribute. s2Member will warn administrators about detected fields that still need review. Fields not whitelisted will not be displayed. Sites using `show_fields` should review _General Options > Shortcode User Fields Whitelist_ and allow the fields their Member Lists are intended to display.
445
446 - (Pro) **Security:** Added safer handling and a whitelist for the `template` shortcode attribute, used by the `s2Member-List`, `s2Member-List-Search-Box`, and Stripe, PayPal, and Authorize.Net Pro-Forms shortcodes. s2Member will warn administrators about detected templates that still need review. Templates not whitelisted will not be used, and the standard template will be used instead. Sites using custom templates should review _General Options > Pro Shortcode Templates Whitelist_ and allow their custom template files.
447
448 - (Pro) **Fix:** Prevented the Pro updater from offering or installing a Pro release newer than the installed s2Member Framework, avoiding compatibility issues until the Framework is updated first.
449
450 - (Pro) **Fix:** Prevented Stripe payment processing from continuing after Pro-Form validation rejects a submission, avoiding misleading Stripe card-field errors when other required form fields are missing.
451
452 - (Pro) **Fix:** Updated Stripe Pro-Forms to use the shortcode's `validate_zipcode` attribute correctly, so it can override the default setting to collect and validate the card's postal code.
453
454 = v260805 =
455
456 - (Framework) **Improvement:** Replaced TinyURL-based shortening for generated Registration Access and Specific Post/Page Access URLs with new built-in s2Member short links, stored temporarily with WordPress transients. Existing TinyURL settings now use the built-in shortener automatically, avoiding TinyURL’s deprecated no-key API endpoint and extra third-party pages shown before the destination.
457
458 - (Framework) **Improvement:** Better PayPal Checkout cancellation button handling when stored IPN Signup Vars are missing. s2Member now checks PayPal subscription details via API before cancellation, uses PayPal's next billing time plus the configured EOT grace period for the EOT time, and falls back to PayPal's subscription management page when a safe local cancellation cannot be completed. See [thread 13462](https://f.wpsharks.com/t/13462).
459
460 - (Framework) **Security:** Hardened the `[s2Stream]` shortcode against executable JavaScript injection by users with post-editing privileges. Attributes used to configure JW Player are sanitized and validated more strictly, and custom `player_path` values must now be explicitly whitelisted using the `ws_plugin__s2member_sc_get_stream_player_paths` filter.
461
462 - (Framework) **Security:** Improved sanitization of sensitive data in s2Member debug logs.
463
464 - (Framework) **Fix:** Prevented a PHP 8+ fatal error during PayPal Standard PDT/IPN return handling when PayPal reports an invalid or unexpected charset. PayPal return data is now converted to UTF-8 defensively, with fallback handling when the reported charset is not accepted by `mb_convert_encoding()`.
465
466 - (Pro) **Improvement:** Added safer handling for rare Stripe Pro-Form subscription checkouts where the first payment or setup confirmation remains pending. s2Member now delays paid-access changes until Stripe confirms the subscription is ready, helping avoid premature access while reducing the chance of confirmed Stripe subscriptions not matching s2Member access.
467
468 - (Pro) **Fix:** Fixed validation of zero-like trial period values such as `tp="0.00"`, so they are treated the same as `tp="0"` instead of being rejected as an invalid trial period.
469
470 = v260508 =
471
472 - (Framework) **Fix:** PayPal Checkout cancellation shortcodes now keep `output="anchor"` clickable for logged-out visitors. Only `output="button"` requires the member to be logged in. See [thread 13450](https://f.wpsharks.com/t/13450)
473
474 - (Framework) **Fix:** PayPal Checkout no longer aborts if the customer's IP address changes during checkout. IP mismatches are logged, but valid checkouts continue processing.
475
476 - (Framework) **Fix:** Prevent false Auto-EOT demotions when a stored Auto-EOT time is `0`, and improve logging for invalid Auto-EOT values. See [thread 13412](https://f.wpsharks.com/t/13412)
477
478 - (Framework) **Fix:** Prevented a PHP 8.1+ deprecation notice while reading registration times when the stored value is missing or false.
479
480 - (Framework) **Improvement:** Improved PayPal Checkout button loading with a client-side fallback when the PayPal SDK is missing from the final page output.
481
482 - (Pro) **Fix:** Prevented deprecation notices on newer PHP versions, which could interfere with automatic login/redirects after Stripe checkout.
483
484 - (Pro) **UI:** Improved cancellation pro-form submit button text. Cancellation forms now say “Cancel Subscription” instead of the generic “Submit Form”. See [thread 13438](https://f.wpsharks.com/t/13438)
485
486 = v260410 =
487
488 - (Framework) **Fix:** Reduced the upfront requirements for processing PayPal Standard `subscr_cancel` IPNs so valid cancellations are not ignored when supporting values are missing, stale, or non-membership-specific.
489
490 - (Framework) **Fix:** Prevent incorrect s2Member notifications in some PayPal Checkout cases where several webhooks are received about the same subscription.
491
492 - (Framework) **Fix:** Prevent duplicate processing and notifications when PayPal sends both a webhook and an IPN for the same PayPal Checkout subscription payment.
493
494 - (Framework) **Fix:** Added subscription modification cancellation support to the Framework, which was previously only available in the Pro addon.
495
496 - (Pro) **Fix:** Made subscription modification cancellation gateway-aware, preventing orphaned active subscriptions when a member starts a replacement subscription through a different gateway.
497
498 - (Pro) **Fix:** Prevented rare cases where subscription modification processing could cancel the newly created subscription by mistake.
499
500 - (Pro) **Fix:** Improved Stripe customer lookup during checkout retries by falling back to email when the stored Stripe customer ID is missing, stale, or no longer retrievable.
501
502 = v260325 =
503
504 - (Framework) **Fix:** Improved PayPal Checkout webhook idempotency to prevent duplicate processing during repeated/concurrent webhooks, while preserving normal behavior.
505
506 - (Framework) **Fix:** Resolved a PayPal IPN issue where some `subscr_cancel` notifications were ignored because the cancellation handler failed before it had fully identified the recurring subscription.
507
508 - (Framework) **Improvement:** Added IPN Signup Var lookups for missing PayPal cancellation IPN values like `period1`, `period3`, `item_number`, `item_name`, and `payer_email`, preventing valid `subscr_cancel` notifications from being ignored.
509
510 - (Framework) **Improvement:** Moved s2Member's translation files to `/languages`, following the WordPress standard, and updated `.mo` loading to support that directory while continuing to support the standard and legacy WordPress locations.
511
512 - (Framework) **Improvement:** Hardened PayPal Standard IPN endpoint response handling and added debug logging for hosts/security layers that incorrectly return HTTP 403 after successful processing.
513
514 - (Framework) **Enhancement:** Added `ukpostcode` as an expected-value option for Custom Registration/Profile Fields, with matching server-side and client-side validation for UK postcode input. The validation is designed to be reasonably broad, including standard UK formats and related special cases. Thanks to Gerard Earley for contributing the patch. See [thread 12200](https://f.wpsharks.com/t/12200)
515
516 - (Framework) **Enhancement:** Added a new __General Options > s2Get Shortcode__ setting to allow `user_id` for whitelisted user fields, defaulting to current-user. Also updated the s2Get KB article accordingly.
517
518 - (Pro) **Fix:** Updated Stripe card charge and PaymentIntent requests to use `statement_descriptor_suffix` instead of `statement_descriptor`, fixing card-payment errors where Stripe no longer accepts `statement_descriptor` for card payments.
519
520 - (Pro) **Fix:** Corrected Stripe subscription checkout so resumed PaymentIntent flows no longer go through the wrong intent-status handler.
521
522 - (Pro) **Fix:** Stripe now stops cleanly after card declines, instead of continuing into secondary intent/payment-method errors.
523
524 - (Pro) **Fix:** Improved Stripe recurring-payment setup to better support future-charge authorization requirements, fixing failures in countries with stricter payment rules, including India.
525
526 - (Pro) **Fix:** Stripe now updates recurring default payment methods only after a successful intent result, instead of earlier in checkout.
527
528 - (Pro) **Fix:** Billing-update SetupIntent creation failures in Stripe now return the proper error response.
529
530 - (Pro) **Fix:** Prevent duplicate/retried Stripe webhook events from being processed more than once, including near-simultaneous retries of the same Stripe event ID
531
532 - (Pro) **Fix:** prevent Stripe billing modification/replacement from triggering EOT behavior for the cancelled old subscription while s2Member is still updating the member account with the new subscription.
533
534 - (Pro) **Fix:** Removed a trailing-comma syntax issue in Stripe subscription update code that could cause PHP compatibility errors on older supported PHP versions.
535
536 - (Pro) **Fix:** s2Member now cleans up incomplete subscriptions left behind by failed 3D Secure authentication attempts during Stripe checkout, and gives the customer a more clear payment failure message.
537
538 - (Pro) **Improvement:** Added dedicated s2 Stripe log entries for non-fatal failures while updating the default payment method after successful intent completion.
539
540 = v260312 =
541
542 - (Framework) **Fix:** Prevent a PHP 8.1+ deprecation notice from appearing above the admin Users table in some cases.
543
544 - (Framework) **Security:** Improved debug log sanitization.
545
546 - (Framework) **Improvement:** PayPal Checkout credential test and OAuth failure log entries now include client_len_hash / secret_len_hash values (length_hash, e.g. 80_4d9a7c1b2e8f4a21) to help compare attempted credentials during troubleshooting without exposing raw values.
547
548 - (Framework) **Enhancement:** Added a new _No-Cache Headers Behavior_ option under _General Options > Performance & Caching_, making no-cache behavior configurable from the admin UI. It includes:
549 - `Always` mode, the legacy safe default that prevents caching site-wide in case user-conditional output appears.
550 - `Selective` mode, which was previously available only through a filter and may improve caching for guests, but can miss some runtime no-cache triggers.
551 - The new `Evaluative` beta mode, which evaluates the page with more runtime information and may allow more pages to be cached safely for guests.
552 - An optional debug header to help troubleshoot no-cache behavior.
553
554 - (Framework) **UI:** Clarified the Download Options text to explain that unique download limits are counted in the last X days (rolling window), reducing confusion about whether the limit resets on fixed calendar dates.
555
556 - (Framework) **UI**: Improved the PayPal Checkout credentials test failure message.
557
558 - (Framework) **UI:** Fixed the PayPal button encryption admin notice so that it shows only to administrators in the WP Admin area, not non-admin users.
559
560 = v260301 =
561
562 - (Framework) **Bug Fix:** Fixed mismatched `<label for="">` and `<input id="">` attributes for checkbox/radio options in Custom Registration/Profile Fields; this also restores proper client-side validation for required checkbox/radio groups.
563
564 - (Framework) **Fix:** Hardened the Edit User Profile screen on PHP 8+ to avoid errors if a user’s Auto-EOT time is stored as a date string (e.g. YYYY-MM-DD) rather than a Unix timestamp (as can happen after imports/migrations).
565
566 - (Framework) **Fix:** Fixed PHP 8+ "Undefined array key" warnings related to membership level label constants (including guest/non-logged-in access label handling).
567
568 - (Framework) **Fix:** Resolved an issue that prevented PayPal Buttons "Generate Button Code" from working in some installations.
569
570 - (Framework) **Fix:** Some PayPal Checkout log entries were missing the environment (sandbox/live), and now include it to help with troubleshooting.
571
572 - (Framework) **Fix:** PayPal Checkout webhooks can continue processing existing subscriptions even if new sales are switched back to PayPal Standard.
573
574 - (Framework) **Fix:** PayPal Checkout webhooks now also handle refunds, reversals, and additional subscription lifecycle events, improving user EOT/access updates and subscription state handling.
575
576 - (Framework) **Fix:** Improved PayPal Checkout amount decimal normalization to prevent one-time payment validation mismatches.
577
578 - (Framework) **Fix:** Updated PayPal Checkout webhook handling to prevent one-time payment captures from being processed as recurring payments.
579
580 - (Framework & Pro) **Fix:** Prevent PHP 8.1+ deprecation warnings in gateway Pro-Forms and related checkout processing (Stripe, PayPal Pro, Authorize.Net), and in custom registration fields, by ensuring optional form/template values are cast to strings before escaping/processing.
581
582 - (Framework) **Security:** Improved debug log sanitization (passwords, API secrets, auth credentials) and reduced post-registration plaintext password exposure.
583
584 - (Framework) **Improvement:** PayPal Standard and PayPal Checkout cancellation buttons now use PayPal’s subscription management page when needed.
585
586 - (Framework) **Improvement:** Better HTTPS detection in s2Member’s PayPal Checkout setup for sites using Cloudflare (or other reverse proxies), reducing false setup failures when enabling or configuring PayPal Checkout.
587
588 - (Pro) **Improvement:** Hardened the Advanced Importer to normalize Auto-EOT values given as date strings (e.g. YYYY-MM-DD) into Unix timestamps when a date is used instead of the expected timestamp format.
589
590 - (Pro) **Improvement:** PayPal Checkout buttons now support `accept="card"` in Pro button attributes, enabling card funding/guest checkout where PayPal makes it available.
591
592 = v260215 =
593
594 - (Framework) **Bug Fix:** Prevent PHP fatal error when multiple PayPal Checkout buttons appear on the same page (PHP 8+).
595
596 - (Framework) **Bug Fix:** PayPal Checkout admin actions (Test Credentials / Webhook / Clear Cache) now submit via POST instead of redirecting (avoids “headers already sent” warnings).
597
598 - (Framework) **Bug Fix:** PayPal cancellation notifications now backfill missing membership mapping fields (`item_number`, `item_name`, `period1`, `period3`) from stored IPN Signup Vars using the subscription ID ( `recurring_payment_id` / `subscr_id` ), so Auto-EOT is set correctly on cancel.
599
600 - (Framework) **Bug Fix:** Auto-EOT PayPal status checks now query PayPal Checkout subscriptions via PayPal’s REST Subscriptions API (instead of PayPal's legacy “Recurring Payments” API), preventing “11592” errors and allowing Auto-EOT to detect inactive PayPal Checkout subscriptions.
601
602 - (Framework) **Security:** PayPal Checkout webhook environment inference now validates the `paypal-cert-url` host before using it (hardens environment inference used during verification).
603
604 - (Framework) **Security:** PayPal Checkout cancel redirect now validates the destination URL and safely falls back to the site home URL.
605
606 - (Framework) **Security:** PayPal Checkout tokens now use s2Member’s hardened unserialize routine.
607
608 - (Framework) **Security:** Harden unserialization of stored custom capabilities metadata when loading user access rules.
609
610 - (Framework) **Security:** Harden the registration password handler.
611
612 - (Framework) **Improvement:** Harden PayPal Checkout endpoint behavior on problematic hosts; return consistent JSON errors (HTTP 500) on notify-proxy failures.
613
614 - (Framework) **Improvement:** Harden PayPal Checkout REST API/webhook handling for network failures and unexpected/non-JSON responses (avoids PHP 8+ warnings).
615
616 - (Framework) **Improvement:** PayPal Checkout webhook setup now treats "no change" updates and existing webhook URLs as success (adopts the existing webhook ID automatically).
617
618 - (Framework) **Improvement:** PayPal Checkout webhook signature verification now auto-detects Sandbox vs Live from inbound headers (so webhooks validate correctly even if the site’s current environment setting differs).
619
620 - (Framework) **Improvement:** PayPal Checkout logging now includes `env_setting` (site setting) and `env_webhook` (inferred from inbound webhook headers) for clearer Sandbox/Live environment troubleshooting.
621
622 - (Framework) **Improvement:** PayPal Checkout webhook idempotency cache (event/txn transients) now retains entries for 1 year (reduces long-term option bloat while preserving replay protection).
623
624 - (Framework) **Improvement:** s2Member’s PayPal “Unsubscribe” button links to PayPal’s subscription management page, and with the new PayPal Checkout integration, when `output="button"` and a PayPal subscription ID is present, s2Member will attempt to cancel the subscription directly.
625
626 - (Framework) **UI:** Add a description for `paypal-checkout.log` in the Log Viewer dropdown (so it’s not “No description available”).
627
628 - (Pro) **Improvement:** PayPal Checkout buttons now support `accept="card"` to enable guest debit/credit card payment in the PayPal-hosted checkout experience when available (availability depends on PayPal settings/eligibility and browser privacy protections).
629
630 = v260127 =
631
632 - (Framework) **PayPal Enhancement**: Modernized s2Member’s PayPal integration by adding support for PayPal Checkout with their latest REST APIs, Smart Buttons, and webhook event handling. This release introduces PayPal’s current Checkout platform as an optional, reliable alternative to the legacy PayPal Standard buttons. Existing s2Member PayPal button shortcodes continue to work as-is (no edits required). See: _WP Admin > s2Member > PayPal Options > PayPal Checkout (Beta)_. Thanks to the beta testers, especially Sim Architect.
633
634 = v260101 =
635
636 - (Framework) **Security**: Improved sanitization and normalization of attribute values for the s2Eot, s2Stream and s2Member-Security-Badge shortcodes.
637
638 - (Framework) **Security**: Improved sanitization of replacement values for confirmation and notification emails.
639
640 = v251005 =
641
642 - (Framework) **Security**: Improved sanitization for Tracking API replacement values.
643
644 - (Framework) **Fix**: Use the site URL host instead of HTTP_HOST for proxy key when Skip Domain Check is enabled.
645
646 - (Framework) **Fix**: Ensure the Fallback IPN Signup Vars provide a valid item_number for cancellation handling.
647
648 = v250905 =
649
650 - (Framework) **Security**: Improve handling of registration fields in multisite.
651
652 - (Framework & Pro) **UI**: Add a Help panel with contact form to all admin pages.
653
654 = v250701 =
655
656 - (Framework & Pro) **Enhancement**: s2Member now supports sending emails in HTML format, allowing for richer, styled messages with formatting, links, and branding. You can enable this feature under _General Options > Email Configuration > Enable HTML Emails_. When disabled, emails continue to use plain text as before. This feature is currently in beta, so feedback is welcome!
657
658 = v250607 =
659
660 - (Framework & Pro) **Enhancement**: Added a new option to skip the domain validation for notifications from the payment gateways. This allows continued processing of incoming notifications even if the domain in the `custom` value doesn't match the current site's. Useful for subscriptions originated outside of s2Member, or under a different domain. The setting is available under: _WP Admin > s2Member > PayPal Options > PayPal IPN / Instant Payment Notifications_
661
662 - (Pro) **UI**: Added the recent IPN Signup Vars Fallback and new Skip Domain Validation to all the gateway options pages.
663
664 - (Framework) **Enhancement**: Added the site's language code when loading the reCaptcha.
665
666 - (Pro) **UI**: Added a page refresh after the Pro Updater finishes installing the latest Pro release, to update the WP Admin interface and not show the Pro Updater again.
667
668 - (Pro) **UI**: Added a page refresh after the Other Gateways options are saved, to update the WP Admin left menu.
669
670 = v250525 =
671
672 - (Framework & Pro) **Fix**: Some translations were being applied too early, causing PHP notices since WP 6.7. Now all translations are only loaded at the `init` hook or later. See [thread 12813](https://f.wpsharks.com/t/12813)
673
674 = v250511 =
675
676 - (Framework) **Fix**: Improved the admin notices handler to prevent a PHP 8.1+ error in rare cases when the data wasn't an array as expected.
677
678 - (Framework) **Enhancement**: Added sanitization to the admin notices handler for improved safety.
679
680 - (Framework & Pro) **Fix**: Updated all uses of preg_split() with `-1` instead of `NULL` as the limit to prevent PHP 8.1+ deprecation warnings.
681
682 - (Pro) **Fix**: Fixed an s2Member-List database query with a typo that prevented some custom searches from working as expected.
683
684 - (Pro) **Fix**: Removed a check in Stripe pro-forms that blocked using the same details for trial and regular payments for subscriptions. See [thread 12818](https://f.wpsharks.com/t/12818).
685
686 = v250502 =
687
688 - (Pro) **Enhancement**: Added optional fallback behavior for missing IPN Signup Vars during Stripe webhook processing. When enabled, s2Member will generate a makeshift IPN vars array if none are stored for the user. This helps support migrated or manually imported subscriptions. The setting is available under _s2Member Pro > Stripe Options > Stripe Webhook/IPN Integration_. See [thread 11334](https://f.wpsharks.com/t/11334).
689
690 - (Framework) **UI**: Removed admin notice about Easter promo for Pro add-on.
691
692 = v250424 =
693
694 - (Framework) **Enhancement**: Added additional sanitation/validation to the Logs Viewer, although only Administrators have access to it.
695
696 = v250419 =
697
698 - (Pro) **Enhancement**: Improved the new coupon code limit per user which prevents a user from applying a coupon code unlimited times, Instead of single use, it can now be limited to more uses, e.g. 3. It's been renamed from "User Once" to "User Max", max number of times a user can use that coupon. This is optional and leaving it blank will give the default "no limit".
699
700 - (Pro) **Enhancement**: Improved validation of the template attribute in the s2Member-List-Search-Box shortcode.
701
702 - (Framework) **UI**: Temporary admin notice about Easter promo for Pro add-on at 20% off.
703
704 = v250214 =
705
706 - (Pro) **Enhancement**: Improved coupon usage logging for better tracking.
707
708 - (Pro) **Enhancement**: Added a new single-use per user option for coupons. Thanks to Carl Borsani for sponsoring this.
709
710 - (Pro) **Enhancement**: Coupons can now be limited to specific pro-forms. Thanks to Carl Borsani for sponsoring this.
711
712 - (Framework) **Fix**: s2Get can now handle s2Member’s custom profile fields. Thanks to Gerard Earley for reporting this.
713
714 - (Framework) **Fix**: Updated the admin notice about the PayPal button encryption setting.
715
716 - (Pro) **Enhancement**: Improved data handling in the Remote Operations API. Props to István.
717
718 - (Pro) **Enhancement**: Improved validation of the template attribute in pro-forms and s2Member-List shortcodes. Props to István.
719
720 = v241216 =
721
722 - (Framework) **Enhancement**: Added extra attribute validation to the s2Get shortcode. Props to wcraft.
723
724 - (Framework) **Enhancement**: Improved New User email preparation before send. Props to Hakiduck.
725
726 = v241114 =
727
728 - (Framework & Pro) **Fix**: An error could happen on PHP8 during Pro activation. Fixed in this release.
729
730 - (Framework) **Enhancement**: s2Get shortcode can now be used to show s2's current user constants. E.g. `[s2Get constant="S2MEMBER_CURRENT_USER_DISPLAY_NAME" /]` _WP Admin > s2Member > API / Scripting > s2Member PHP/API Constants_
731
732 = v240325 =
733
734 - (Framework) **Fix**: Some sites were getting a warning from v240315's restriction improvement when the WP REST request doesn't include a type or ID. Fixed in this release. See [thread 11347](https://f.wpsharks.com/t/11347)
735
736 - (Pro) **Enhancement**: Checkout success redirection URLs are now validated as safe with WordPress' _wp_validate_redirect_. To use a domain different than the site's, it can be allowed with wp's filter [allowed_redirect_hosts](https://developer.wordpress.org/reference/hooks/allowed_redirect_hosts/).
737
738 - (Framework) **Enhancement**: Additional validation to prevent an invalid s2Member Level role during registration.
739
740 = v240315 =
741
742 - (Framework) **Enhancement**: Improved access restrictions applied to WP REST requests.
743
744 = v240218 =
745
746 - (Framework) **Fix**: PayPal button encryption default changed to "disabled".
747
748 - (Framework) **Fix**: Mailchimp interest groups integration wasn't working correctly all the time. Fixed in this release.
749
750 = v230815 =
751
752 - (Framework) **Fix**: Added some missing functions to the list of conditionals allowed by default for s2If (e.g. `current_user_days_to_eot_less_than`, `current_user_gateway_is`). See also: https://s2member.com/kb-article/s2if-simple-shortcode-conditionals/#toc-5bb69568
753
754 - (Pro) **Enhancement**: New s2If whitelist option for custom conditional functions to be allowed. _s2Member Pro > Restriction Options > Simple Shortcode Conditionals > Whitelist_
755
756 - (Framework) **Enhancement**: Handle s2If conditional problems more gracefully. Instead of giving an error that prevents loading the rest of the page, it now just doesn't display that s2If's block, and enters a message in the error log (e.g. `/wp-content/debug.log`).
757
758 - (Framework & Pro) **Enhancement**: Prevent output from s2If conditions, only _true_ or _false_.
759
760 - (Framework) **UI**: Update the Mailchimp example from `Group Title` to `Group Category`, to match Mailchimp's current name in their settings. _s2Member > API / List Servers > Mailchimp_
761
762 = v230808 =
763
764 - (Framework) **Fix**: Potential security issue under rare circumstances. Fixed in this release.
765
766 - (Framework) **Fix**: Mailchimp's groups/interests were not transitioning correctly with the updated integration. Fixed in this release.
767
768 - (Framework) **UI**: Added a notice about PayPal giving trouble with encrypted buttons recently, recommending to not encrypt them for now. You may need to disable button encryption, and allow non-encrypted payments. _s2Member > PayPal Options > Account Details > Button Encryption_
769
770 - (Framework) **UI**: Brought back the "Expand All" and "Collapse All" buttons for the admin panels. See [thread 10796](https://f.wpsharks.com/t/10796)
771
772 - (Framework) **UI**: Updated the link to the PayPal IPN configuration.
773
774 - (Framework) **UI**: Added link to PayPal's IPN History page. _s2Member > PayPal Options > PayPal IPN > More Information_
775
776 - (Pro) **Fix**: Stripe's billing update pro-form gave an error sometimes. Fixed in this release. See [thread 10752](https://f.wpsharks.com/t/10752)
777
778 = v230530 =
779
780 - (Framework) **Enhancement**: Updated the Mailchimp integration to v3 of their API. I made it so you shouldn't need to change anything, it should work with your existing configuration. Still worth doing a test or checking that things are normal after the update, and report any issues you notice. See: [thread 10666](https://f.wpsharks.com/t/10666)
781
782 = v230504 =
783
784 - (Pro) **Fix**: Stripe subscriptions weren't using customer cards updated with the Billing Update pro-form. The subscription saved the first card, instead of defaulting to the card in the customer's profile. This release fixes that. The card is not added to a new subscription anymore, only to the customer's profile, and updating his profile's card with the Billing Update pro-form, will also update the subscription so it uses it. Thanks to Jim Antonucci for his help with this.
785
786 - (Pro) **Enhancement**: The Stripe Billing Update pro-form now includes a field for the cardholder's name (i.e. Name On Card). Adding the name to the card will improve successful subscription charges. Thanks to Andy Johnsen for the idea.
787
788 = v230425 =
789
790 - (Framework) **Fix**: Fixed domain name format validation for custom profile fields.
791
792 - (Framework) **Fix**: Fixes to markdown parser for PHP8 compatibility.
793
794 - (Framework) **Fix**: Fixed HTML near AWeber's API key field.
795
796 = v230413 =
797
798 - (Pro) **Bug Fix**: An error could happen on PHP8 during Pro installation in a multisite network. Fixed in this release.
799
800 - (Framework) **Bug Fix**: An error could happen on PHP8 when saving an edited user profile. Fixed in this release.
801
802 - (Framework) **UI Enhancement**: In the List Servers admin page, removed mentions of the AWeber email parser, which isn't available any more.
803
804 = v221103 =
805
806 - (Framework) **Bug Fix**: Removed latest changes to gateway notification and return handlers, that were causing difficulties with member access in some scenarios.
807
808 = v221031 =
809
810 - (Framework) **Bug Fix**: Fix PayPal IPNs being ignored because a bug in the last release. After updating to this release, you may want to [review your latest IPNs](https://www.paypal.com/merchantnotification/ipn/history) since updating to v221028, and re-send them from PayPal. See [thread 10208](https://f.wpsharks.com/t/10208)
811
812 = v221028 =
813
814 - (Framework) **Fix**: Initialized some array keys to prevent PHP warnings in PayPal notify and return files. Thanks Greg M. for your help.
815
816 - (Framework) **UI**: Widened the Logs viewer. Thanks Sim. See [thread 10064](https://f.wpsharks.com/t/10064)
817
818 - (Framework) **UI**: Framework auto-update is now allowed when Pro add-on installed.
819
820 - (Pro) **UI**: The Pro updater now shows when a newer version available, not just when required.
821
822 = v220925 =
823
824 - (Pro) **UI Enhancement**: In ClickBank Options admin page, added note about keeping IPN encryption disabled.
825
826 - (Pro) **Enhancement**: Removed ClickBank's name from the notify, return, and success URLs, replaced with just `cb`. Kudos to Eduardo for telling me about this. See [thread 9910](https://f.wpsharks.com/t/9910)
827
828 - (Pro) **Enhancement**: Added a PayPal payment request ID to help prevent random/rare PayPal duplicate charges. Kudos to Nathan for his help. See [thread 7999](https://f.wpsharks.com/t/7999/27)
829
830 - (Framework) **UI Enhancement**: Admin page panels widened for larger displays.
831
832 - (Framework) **UI Enhancement**: Simplified Getting Started and Getting Help admin pages.
833
834 - (Framework) **UI Enhancement**: In PayPal Options admin page, updated paths and links to PayPal settings.
835
836 - (Framework) **Bug Fix**: Removed the Security Badge's link to the old Flash powered page on s2Member's site.
837
838 - (Pro) **UI Enhancement**: Small improvements to the Pro upgrader.
839
840 = v220809 =
841
842 - (Framework) **Enhancement**: New `current_user_days_to_eot_less_than` function for conditionals. Useful when you want to show a message to a user on his last days of access before the EOT time in his profile. E.g. `[s2If current_user_days_to_eot_less_than(31)]Please renew your membership[/s2If]`. Kudos to Felix for his help, see [post 6783](https://f.wpsharks.com/t/6783).
843
844 = v220421 =
845
846 - (Framework & Pro) **Enhancement**: Improved PHP compatibility to 8.1.
847
848 - (Framework) **UI Fix**: `More Updates` link fixed.
849
850 = v220318 =
851
852 - (Framework) **Enhancement**: New `current_user_gateway_is` function for conditionals. Useful for sites using more than one gateway. E.g. `[s2If current_user_gateway_is(stripe)] ...`
853
854 - (Pro) **UI Fix**: Removed "Image Branding" setting from s2's Stripe options, not used in current integration.
855
856 = v210526 =
857
858 - (s2Member Framework & Pro) **UI Enhancement**: Started improving the admin interface. Lightened up the colors, and changed the layout a little bit.
859
860 - (s2Member Framework) **UI Enhancement**: Added title tag to buttons to manage custom profile fields in admin, to improve use with screen-reader. [Thread 8836](https://f.wpsharks.com/t/8836/12)
861
862 - (s2Member Pro) **UI Fix**: Fixed typo in pro-form `rrt` attribute description. [Issue 1204](https://github.com/wpsharks/s2member/issues/1204)
863
864 - (s2Member Framework) **Bug Fix**: Registration Date sometimes wasn't formatted correctly with the s2Get shortcode. [Thread 8730](https://f.wpsharks.com/t/8730)
865
866 = v210208 =
867
868 - (s2Member Pro) **Enhancement**: In the Stripe integration, cancelling a subscription in the last minutes of a period, may cause the invoice for the new period to remain there and still be charged later. Now s2Member Pro attempts to find a draft or open invoice for the subscription being cancelled, and void it. Thanks Alan for reporting it. See [post 8386](https://f.wpsharks.com/t/8098).
869
870 - (s2Member Pro) **UI Enhancement**: Improved Stripe pro-form error message when trying to create a subscription with a bad card. Thanks everyone that reported it. See [issue #1184](https://github.com/wpsharks/s2member/issues/1184), [post 6043](https://f.wpsharks.com/t/6043), and [post 8386](https://f.wpsharks.com/t/8386).
871
872 - (s2Member Pro) **Enhancement**: Added the new action hooks `ws_plugin__s2member_pro_before_stripe_notify_event_switch` and `ws_plugin__s2member_pro_after_stripe_notify_event_switch` in the Stripe endpoint to allow customizations, e.g. new event handlers.
873
874 - (s2Member Pro) **UI Fix**: Removed some leftover mentions of Bitcoin support in Stripe's options.
875
876 - (s2Member Pro) **UI Fix**: Removed a couple of deprecated shortcode attributes from the documentation for Stripe's pro-form, leftovers from the old integration. Kudos to Debbie for bringing my attention to them. See [post 8053](https://f.wpsharks.com/t/8053).
877
878 - (s2Member Framework) **UI Fix**: Fixed some broken links and video players in the admin pages.
879
880 - (s2Member Framework) **Bug Fix**: Resolved a warning given when changing users role in bulk from the WP Admin > Users page.
881
882 - (s2Member Server Scanner) **Bug Fix**: Updated the [Server Scanner](https://s2member.com/kb-article/server-scanner/) to remove some outdated warnings.
883
884 = v201225 =
885
886 - (s2Member Framework) **Bug Fix**: View Password icon WP's login page was not displaying correctly. Kudos to Beee4life for reporting it. See [issue #1187](https://github.com/wpsharks/s2member/issues/1187)
887
888 - (s2Member Framework and Pro) **Enhancement**: Refactored PHP's deprecated _create_function_ with anonymous functions. Kudos to Berry for reporting it, see [post 6069](https://f.wpsharks.com/t/6069)
889
890 - (s2Member Framework) **Bug Fix**: Added a check for empty return variable before trying to use it in paypal-utilities.inc.php.
891
892 - (s2Member Framework) **Bug Fix**: Added checks for undefined indexes before trying to use them in paypal-return-in-subscr-or-wa-w-level.inc.php.
893
894 - (s2Member Framework) **Bug Fix:** Added a check for undefined index before using it to define a couple of s2 constants. Kudos to Berry for reporting it, see [post 8181](https://f.wpsharks.com/t/8181/)
895
896 - (s2Member Pro) **Bug Fix**: s2's payment notification when creating a Stripe subscription, was being sent twice. Added a check to ignore the webhook for the subscription's on-session first payment; s2's webhook endpoint is for off-session events.
897
898 - (s2Member Framework) **Enhancement**: Added a new hook for the payment notification on subscription creation or buy now payments.
899
900 - (s2Member Pro) **Bug Fix**: Stripe paid trials were accumulating on failed payment attempts, causing a larger charge when it finally succeeded. Kudos to Alan for his help through the many attempts to fix this one, see [post 7002](https://f.wpsharks.com/t/7002).
901
902 - (s2Member Pro) **Enhancement**: Stripe duplicate payments were happening randomly to a few site owners, apparently from bad communication between their server and Stripe's. Added idempotency to prevent duplicates. Kudos to Alan and everyone in the forum that reported and gave details on this behavior, see [post 7002](https://f.wpsharks.com/t/7002)
903
904 = v200301 =
905
906 - (s2Member Pro) **Enhancement:** Added "Powered by Stripe" to Stripe pro-form's payment card field. Kudos to Josh, see [post 6716](https://f.wpsharks.com/t/6716).
907
908 - (s2Member Pro) **Bug Fix:** Stripe subscription cancellations were not happening when they should. This release updates the API integration for it and fixes that behavior. Kudos to Matt for reporting it, see [post 6909](https://f.wpsharks.com/t/6909).
909
910 - (s2Member Pro) **Bug Fix:** Updating the card with Stripe's pro-form sometimes gave an incorrect "missing billing method" error. Kudos to Corey, see [post 7058](https://f.wpsharks.com/t/7058).
911
912 - (s2Member Pro) **Small fix:** Removed Bitcoin mention next to Stripe in Gateways list. Missed it in [v191022](https://s2member.com/s2member-v191022-now-available/).
913
914 = v200221 =
915
916 - (s2Member Pro) **Bug Fix:** In some rare cases, another plugin loaded Stripe's class before s2Member, so when s2 tried loading it there'd be an error. This release fixes the check for the class before trying to load it. See [issue #1170](https://github.com/wpsharks/s2member/issues/1170)
917
918 **Note:** s2Member won't have control over what version of the Stripe SDK was loaded by the other plugin. You'll need to get that other plugin to have an up-to-date version. If you don't have another plugin loading Stripe, this is not relevant to you.
919
920 - (s2Member Pro) **Bug Fix:** When using a 100% off coupon, requiring no payment, the Stripe pro-form was still loading the card field and requiring it, preventing the free signup. That's fixed in this release. See [issue #1171](https://github.com/wpsharks/s2member/issues/1171)
921
922 - (s2Member Pro) **Bug Fix:** The Stripe pro-form, when given an invalid card, didn't give a clear error message for it, and instead just "invalid parameter". Now it shows the correct card error, making it possible for the customer to try a different card to complete the payment.
923
924 - (s2Member Pro) **Feature Update:** The Indian Rupee was added to the list of currency symbols.
925
926 - (s2Member Pro) **Feature Enhancement:** The s2Member Pro add-on, not being a regular plugin was not uploadable via the WP plugin manager. This made it necessary to FTP, which is complicated for some site owners. In this release I made it possible for the plugin manager to upload or remove the Pro add-on.
927
928 **Note:** It still is not a regular plugin. The activation link or status in the plugins manager is irrelevant, but I couldn't find how to remove it. s2Member Pro activates automatically when its version matches the Framework's, and it'll be mentioned next to the Framework's version in the plugins manager.
929
930 = v191022 =
931
932 - (s2Member Pro) **Feature Enhancement:** The Stripe pro-forms can now handle 3D Secure 2 for [Strong Customer Authentication](https://stripe.com/guides/strong-customer-authentication), as required by the new European regulation that came into effect recently. Props to those in the beta testing group, especially Brice and Felix. See [thread 5585](https://f.wpsharks.com/t/5585/).
933
934 - (s2Member Pro) **Feature Enhancement:** The Stripe pro-form now has the card field inline, instead of opening a modal to enter it. Before it required clicking the link to open the modal, enter the card details, submit that, and then submit the pro-form. Now you enter the card details as part of the pro-form. See [issue #588](https://github.com/wpsharks/s2member/issues/588).
935
936 - (s2Member Pro) **Stripe Integration Updates:** Upgraded the Stripe PHP SDK from v1.18 to v7.4.0, and the API from 2015-07-13 to 2019-10-08. Upgraded the integration from the Charges API to the latest Payment Intents API. Upgraded the card input from the old Stripe Checkout modal, to the new Stripe.js and Elements.
937
938 - (s2Member Pro) **Optimization:** Stripe's JavaScript now only gets included if the page has a Stripe pro-form.
939
940 - (s2Member Pro) **Removed Stripe Bitcoin**: Stripe [dropped Bitcoin](https://stripe.com/blog/ending-bitcoin-support) last year, it's not available anymore. This update removes the Bitcoin options and mentions from the s2 admin pages.
941
942 - (s2Member Pro) **Bug Fix:** Subscriptions without at trial were showing a "trialing" status in Stripe for the first period. This behavior has now been solved. It will only say trialing when you set a trial period (free or paid) in your Stripe pro-form shortcode. See [issue #1052](https://github.com/wpsharks/s2member/issues/1052).
943
944 - (s2Member Pro) **Bug Fix:** The Stripe pro-form installments via the `rrt` shortcode attribute were charging an extra payment before ending the subscription. There was an error in the time calculation for this. This is solved in this release. Props to Brice. See [thread 5817](https://f.wpsharks.com/t/5817/).
945
946 - (s2Member Pro) **Bug Fix:** Some payments through the Stripe pro-form were creating a new Stripe customer when the user was already a customer. The Stripe customer ID was not being saved correctly in the user's profile. This is solved in this release. Props to demeritcowboy for reporting it.
947
948 = v190822 =
949
950 - (s2Member) **PayPal Integration Update:** PayPal deprecated the subscription modification button. Using the old possible values for this, now gives an error on PayPal's site. This button has been removed from the PayPal Standard integration in s2Member. Props to Tim for reporting it, see [forum thread 5861](https://f.wpsharks.com/t/5861), and [issue #1157](https://github.com/wpsharks/s2member/issues/1157).
951
952 - (s2Member) **Bug Fix:** PayPal would sometimes return the customer without the Custom Value expected by s2Member, incorrectly triggering an error. A small delay has now been added when needed to wait for PayPal to provide the missing value, so that the customer is met with the correct success message on return. Props to Josh Hartman for his help. See [forum thread 5250](https://f.wpsharks.com/t/5250).
953
954 - (s2Member) **Bug Fix:** Google's URL shortening service has been [discontinued](https://developers.googleblog.com/2018/03/transitioning-google-url-shortener.html). The s2Member integration with it was removed in this release. Props to Felix Hartmann for reporting it.
955
956 - (s2Member) **Feature Enhancement:** The popular URL shortening services have been abused in spam emails, and this can cause your site's emails with shortened signup URLs to end up in the spam folder. It's now possible to disable URL shortening when trying to avoid this problem. Props to Felix Hartmann for suggesting it. See [forum thread 5697](https://f.wpsharks.com/t/5697).
957
958 - (s2Member Pro) **New Feature:** It is now possible to use a custom URL shortener other than the defaults in the s2Member Framework. This is particularly useful to use [YOURLS](http://yourls.org/) for your links, making them unique to your site, looking more professional and avoiding the spam filters issue mentioned above. For more info see this [forum post](https://f.wpsharks.com/t/5697/19).
959
960 = v190617 =
961
962 - (s2Member Pro) **Authorize.Net Hash Upgrade:** Authorize.Net [announced](https://support.authorize.net/s/article/MD5-Hash-End-of-Life-Signature-Key-Replacement) the end-of-life for their MD5 Hash in favor of their new SHA512 Signature Key. Support for this has been added to s2Member Pro. The MD5 Hash is not provided by Authorize.Net any more, so the field for it in s2Member has been disabled. Props @krumch for his work. For further details see [forum thread 5514](https://f.wpsharks.com/t/5514).
963
964 **Note:** For those that already used the MD5 Hash in their configuration, it is kept there and will keep working while Authorize.Net accepts it, which will not be much longer. It's important to update your integration with the new Signature Key. Once you have your Signature Key in the s2Member configuration, it will be favored over the old MD5 Hash._
965
966 - (s2Member Pro) **Bug Fix:** The multisite patch for `wp-admin/user_new.php` wasn't finding the code to replace because of changes in the latest releases of WordPress. It has now been updated, as well as the instructions in the Dashboard for those that prefer to apply it manually. Props @crazycoolcam for reporting it. For further details see [Issue #1132](https://github.com/wpsharks/s2member/issues/1132).
967
968 **Note:** If you already had patched this file in the past, it's recommended that you remove the previous patch restoring it to the original file, and let s2Member Pro patch it again now, otherwise you risk getting it patched over the previous one and ending up with errors. After the new patch, please review that file to verify that it's correct._
969
970 - (s2Member Pro) **Bug Fix:** The search results for `s2Member-List` were not being ordered as specified in the `orderby` attribute when this was a field from the `usermeta` table in the database, e.g. `first_name`, `last_name`. This is now fixed and working correctly. Props to @stevenwolock for reporting it. For further details see [Issue #1103](https://github.com/wpsharks/s2member/issues/1103).
971
972 - (s2Member) **WP 5.2 Compat. Enhancement:** s2Member has been tested with WP up to 5.2.2-alpha. With `WP_DEBUG` enabled, only one "notice" was found. In `wp-login.php` it said 'login_headertitle is deprecated since version 5.2.0! Use login_headertext instead.' This release now uses `login_headertext` and doesn't get that notice anymore. Props Azunga for reporting it. See [forum thread 5962](https://f.wpsharks.com/t/5962).
973
974 You can find the [full changelog here](https://s2member.com/changelog/).
975