| @@ -1,8 +1,208 @@ | ||
| 1 | 1 | === xSpeed Cache — full changelog === |
| 2 | 2 | |
| 3 | 3 | The three most recent releases are listed in readme.txt. Everything since 1.0.0 is below. |
| 4 | 4 | |
| 5 | += [1.4.0] – 2026-10-06 = | |
| 6 | + | |
| 7 | +**Saving a post now clears only the pages it changes instead of the whole cache, sites on xCloud's Cloudflare Enterprise get every purge passed to the edge, and pages whose address uses non-Latin characters are cached and purged correctly.** | |
| 8 | + | |
| 9 | +Caching: | |
| 10 | +- New: Saving a post, a comment or a product clears only the pages that change: the post itself, its archives, and the listing pages that show it. The whole cache is cleared only when the change reaches a list the theme draws on every page, such as a menu or a Recent Posts widget, and the purge log says why. | |
| 11 | +- New: `wp xspeed cache listings` shows the pages that run a post list of their own. | |
| 12 | +- New: Add-ons can send CDN headers on cached pages. | |
| 13 | +- Fixed: Pages whose address uses non-Latin characters, such as Chinese or Arabic slugs, each get their own cache entry. They could share one, and a slug with no Latin letters could overwrite the home page's cached copy. | |
| 14 | +- Fixed: A purge clears such a page however the browser spells its address, and Excluded URLs pasted from the address bar now match. | |
| 15 | +- Fixed: Opening wp-admin no longer empties the page cache and the edge. | |
| 16 | +- Fixed: Updating a WooCommerce product purges once, and a stock change purges its pages in one batch. | |
| 17 | +- Fixed: Making a post sticky, including outside the editor, clears the blog page. | |
| 18 | +- Fixed: Publishing in the Customizer purges the cache. | |
| 19 | +- Fixed: Content and site purges no longer delete minified CSS and JS files. | |
| 20 | + | |
| 21 | +Cloudflare: | |
| 22 | +- New: On sites where xCloud provides Cloudflare Enterprise, every purge goes to xCloud's purge plugin, from WP-CLI and cron too, and Purge All sends one whole-domain purge. | |
| 23 | +- New: xCloud's purge plugin counts as proof that the site is behind Cloudflare. | |
| 24 | +- Fixed: The edge no longer keeps a page longer than the page's own lifetime, so forms on cached pages stop failing once their nonce expires. | |
| 25 | +- Fixed: Pages served for an address with tracking parameters, such as `?utm_source=`, are no longer stored at the edge, where a purge could not reach them. | |
| 26 | +- Fixed: The edge may store a new page only once xSpeed has written it, and not while the page is still being optimized. | |
| 27 | +- Fixed: Edge headers are kept on cached pages Apache serves through an internal redirect. | |
| 28 | + | |
| 29 | +Health: | |
| 30 | +- New: Health warns when Cloudflare stores pages that were marked do-not-store. | |
| 31 | +- New: The nginx rules panel says whether the server runs the current rules block, and remembers that you pasted it. | |
| 32 | + | |
| 33 | +Optimization: | |
| 34 | +- Fixed: Minified and combined files are named by their content and by site, so a changed source file is never served from an old copy. | |
| 35 | +- Fixed: Delay JS restarts its 15-second replay deadline each time a delayed script arrives, so slow pages finish replaying. | |
| 36 | +- Fixed: Smart Delay never parks the inline snippets of a script that is already running, and consent-banner protection ignores the site's own domain. | |
| 37 | +- Fixed: Text set in the Font Library or theme.json shows at once while its fonts load. | |
| 38 | +- Improved: Turbo Render holds a deferred section's images and videos until the section is near. | |
| 39 | + | |
| 40 | +Media: | |
| 41 | +- New: Autoplay videos can start after the page has loaded. Off by default. | |
| 42 | +- Fixed: Autoplay videos stay out of the click-to-play facade, and the video restorer respects Excluded Images. | |
| 43 | +- Fixed: Images in footer popups load a smaller file on phones. | |
| 44 | + | |
| 45 | +Resource Hints: | |
| 46 | +- Fixed: Device-scoped LCP preloads fetch only the hero image for the visitor's device. | |
| 47 | + | |
| 48 | +Preloader: | |
| 49 | +- New: With Separate Mobile Cache on, the preloader warms the phone copy of each page too. | |
| 50 | + | |
| 51 | +Object Cache: | |
| 52 | +- Fixed: Switching from another object-cache plugin works without a conflict, and switching back restores that plugin on a clean namespace. | |
| 53 | + | |
| 54 | +AI / MCP: | |
| 55 | +- New: A site can be connected from xSpeed Hub through a consent page in wp-admin. | |
| 56 | +- New: get_site_info reports add-on licences. | |
| 57 | +- Fixed: The site token is never sent to a redirect target, and a connection code works only once. | |
| 58 | +- Fixed: Saving settings over MCP could remove the site's Hub connection. | |
| 59 | +- Fixed: Destructive commands need confirmation however they are called. | |
| 60 | + | |
| 61 | +Dashboard & Admin UX: | |
| 62 | +- New: The Cloudflare Enterprise add-on has its own entry under Network, a sidebar card and a purchase screen. | |
| 63 | +- Fixed: A Pro module shows the Pro lock while Pro is unlicensed. | |
| 64 | +- Fixed: Dashboard requests work on sites whose REST address carries a query string. | |
| 65 | +- Fixed: The dashboard no longer shows a second scrollbar. | |
| 66 | + | |
| 67 | += [1.3.7] – 2026-09-30 = | |
| 68 | + | |
| 69 | +**Pages with a background-video hero now paint the hero text first, Load CSS Asynchronously no longer makes pages flash unstyled, sites in a multisite network stop sharing cached REST responses, and a site whose token changed can reconnect to xSpeed Hub.** | |
| 70 | + | |
| 71 | +Media: | |
| 72 | +- Fixed: A hero's background video (autoplay, muted, looping, no controls or poster) now starts on the visitor's first scroll, tap, key press or mouse move, so the hero text paints first instead of waiting for the video's first frame. | |
| 73 | +- Fixed: Only one image per page gets high fetch priority, instead of every image counted by Eager-load First N Images. | |
| 74 | + | |
| 75 | +Optimization: | |
| 76 | +- Fixed: Load CSS Asynchronously leaves stylesheets render-blocking unless the page has critical CSS, so pages no longer paint unstyled and then shift. Google Fonts, Bunny and Typekit stylesheets still load without blocking. | |
| 77 | +- Fixed: A page builder's row, column and section stylesheets stay render-blocking, so a builder hero no longer snaps into its grid after the first paint. | |
| 78 | +- Fixed: Under Delay JS, a script's inline data now waits with the script, so the script never runs without its data. | |
| 79 | +- Fixed: Combine CSS recognises another plugin's non-blocking stylesheet however its onload handler is written, instead of merging it into a print-only file. | |
| 80 | +- Fixed: Strip jQuery Migrate works when another plugin, such as Elementor Pro, loads the script registry before Bloat Control. | |
| 81 | + | |
| 82 | +Resource Hints: | |
| 83 | +- Fixed: When a background video opens the page, images below it are no longer preloaded as the LCP image. | |
| 84 | + | |
| 85 | +Caching: | |
| 86 | +- Improved: More click and campaign IDs are ignored in the cache key, on saved lists too. | |
| 87 | +- Fixed: Each site in a multisite network gets its own cached REST responses. Two sites requesting the same route could be served each other's data. | |
| 88 | +- Fixed: Installing a new plugin no longer empties the page cache as if live code had been replaced. | |
| 89 | +- Fixed: A request that measures a page's CSS is never answered from cache, whatever Ignored Query Parameters say. | |
| 90 | +- Fixed: xSpeed's own warming, benchmark and verifier requests, and bot hits, no longer count in the hit ratio or in site analytics. | |
| 91 | + | |
| 92 | +AI / MCP: | |
| 93 | +- New: Extensions can add hidden MCP tools, and oversized MCP request bodies are refused. | |
| 94 | +- Improved: The generate_critical_css tool builds Critical CSS for any page, not only the home page. | |
| 95 | +- Improved: get_cache_status reports the Site Icon. | |
| 96 | +- Fixed: A site whose MCP token changed can reconnect to xSpeed Hub. The Hub gets the new token, and a new credential clears its lockout. | |
| 97 | +- Fixed: The attach route no longer returns the admin's user ID. | |
| 98 | + | |
| 99 | +Dashboard & Admin UX: | |
| 100 | +- Improved: Settings labels and hints are rewritten in plain language and sentence case. | |
| 101 | +- Fixed: Leaving onboarding from the last step lands on the dashboard instead of a broken #[object Object] page. | |
| 102 | + | |
| 103 | += [1.3.6] – 2026-09-28 = | |
| 104 | + | |
| 105 | +**Smart Delay postpones the scripts other delay modes had to leave running, LCP background images and video posters are preloaded, LiteSpeed servers get the same static fast path nginx and Apache already had, lightbox videos open with their player instead of a blank window, and Turbo Render no longer clips designs that overlap their neighbours. Emojis can be switched off, post revisions capped, and inline background images held back until they scroll into view.** | |
| 106 | + | |
| 107 | +Media: | |
| 108 | +- New: Background images set in an element's inline style can be lazy-loaded. Each one loads just before its element scrolls into view, the first ones on the page load straight away (the Eager-load First N Images count), and with JavaScript off every background loads as before. Off by default. | |
| 109 | +- Fixed: A video embed inside a lightbox's hidden template (Essential Addons, Magnific Popup, Lity) is no longer swapped for the click-to-play facade — the popup opened blank because lightbox styling only sizes an iframe. The template's iframe stays lazy, so it still loads nothing until the popup opens, and the list of template classes can be extended with the xspeed_video_facade_popup_classes filter. | |
| 110 | + | |
| 111 | +Optimization: | |
| 112 | +- New: Bloat Control has a Disable Emojis toggle. It removes the WordPress emoji script and styles from pages, feeds, emails, embeds and wp-admin. Off by default. | |
| 113 | +- New: Smart Delay. Delaying every script used to quietly skip any script that inline code depends on — on builder pages that was most of them. Smart Delay postpones those scripts anyway and parks their inline snippets with them, replaying everything in page order on the first interaction. Off by default; the exclusion list and consent-banner protection still win. | |
| 114 | +- New: Turbo Render has an Excluded classes setting. A deferred section clips content that hangs over its boundary — a card overlapping the section below it, for example — so a section listed here always renders right away. | |
| 115 | +- Improved: Delayed scripts now replay the way a real page loads — in page order, with the document's readyState moving through its normal stages, and with each script's DOMContentLoaded and load handlers firing when its turn comes. | |
| 116 | +- Improved: A delayed inline loader now waits for the scripts it injects, a throwing inline module no longer stalls the replay behind it, and the replay works on pages with a hash-based Content-Security-Policy. | |
| 117 | +- Fixed: Turbo Render leaves any section holding an iframe alone. Deferring a map or video holder gained nothing and could paint it over content that overlaps it by design. | |
| 118 | +- Fixed: The replay no longer touches scripts and handlers the page ran normally — their writes, listeners and onreadystatechange calls behave exactly as before Delay JS was switched on. | |
| 119 | +- Fixed: A consent banner is only delayed by an entry that names it; a second protected token on the same tag now needs naming too. | |
| 120 | +- Fixed: A script whose author opted out of optimization late in the page no longer loses the defer attribute a stamper had already given it. | |
| 121 | + | |
| 122 | +Resource Hints: | |
| 123 | +- New: LCP background images declared in <style> rules and video poster images are now detected and preloaded, so hero sections painted from CSS backgrounds get the same head start as <img> heroes. | |
| 124 | + | |
| 125 | +Caching: | |
| 126 | +- New: LiteSpeed servers can opt into the static-rewrite fast path, serving cached pages before PHP starts — the same shortcut nginx and Apache sites already had. | |
| 127 | +- Fixed: Publishing a post on an nginx host no longer purges the server's entire cache — only the pages the post touches. Nginx Helper's own off switch is respected, and a content import ends with one server purge instead of one per post. | |
| 128 | +- Fixed: The admin-bar purge button answers immediately and runs the purge in the background, instead of holding the request open until some hosts cut it off. | |
| 129 | + | |
| 130 | +Database: | |
| 131 | +- New: Limit Post Revisions keeps only as many revisions per post as you choose, and 0 turns revisions off. A WP_POST_REVISIONS value in wp-config.php still wins, and the panel shows it. | |
| 132 | + | |
| 133 | +Migration: | |
| 134 | +- Fixed: Importing LiteSpeed Cache settings no longer turns oEmbed off when the site had emoji removal on. That setting now maps to Disable Emojis. | |
| 135 | +- New: WP Rocket's emoji, embeds and CSS background lazy-load settings are imported. | |
| 136 | + | |
| 137 | +Dashboard & Admin UX: | |
| 138 | +- Fixed: The Cloudflare upsell no longer advertises an edge cache TTL the APO module does not set. | |
| 139 | + | |
| 140 | += [1.3.5] – 2026-09-22 = | |
| 141 | + | |
| 142 | +**Consent banners now survive Delay JS on every site that ships one, Turbo Render works on any theme rather than only Elementor, JS-injected YouTube/Vimeo embeds load only on click, and nginx sites are no longer told to fix a configuration that was already correct.** | |
| 143 | + | |
| 144 | +Media: | |
| 145 | +- New: YouTube and Vimeo players that a theme or plugin injects with JavaScript after page load now get the same click-to-load facade as regular embeds, so no player code loads until a visitor presses play. | |
| 146 | + | |
| 147 | +Optimization: | |
| 148 | +- New: Turbo Render works on any theme or page builder. It recognises Divi, Bricks, Oxygen and Beaver Builder sections directly, and where no builder is recognised it falls back to the page's own structure, so the feature is no longer inert outside Elementor. | |
| 149 | +- Improved: Turbo Render is the new name for the feature previously called Render Skip — the same mechanism, named for what the visitor gets rather than what the browser postpones. | |
| 150 | +- Fixed: Consent banners from Cookie Notice, Moove, Termly, Usercentrics, Iubenda, OneTrust, Borlabs, Real Cookie Banner and SureCookie are never delayed, so a visitor is always offered the choice before leaving. | |
| 151 | +- Fixed: Complianz and NotificationX banners stay protected even when another plugin strips the id WordPress prints on their script. | |
| 152 | +- Fixed: An author's data-no-optimize, nowprocket or similar opt-out is now read as an attribute rather than matched anywhere in the tag, so a script is neither wrongly delayed nor wrongly skipped because the marker appeared in a URL, a class or a neighbouring inline block. | |
| 153 | +- Fixed: A script you name yourself in the Delay JS target list is now delayed even when it is a consent banner — the built-in banner protection yields to an explicit choice. | |
| 154 | + | |
| 155 | +Health: | |
| 156 | +- Fixed: nginx sites with a working configuration are no longer told to paste in a server snippet they already have. Site Health and the dashboard now reach the same verdict, and a check that cannot conclude says so instead of warning. | |
| 157 | + | |
| 158 | +Preloader: | |
| 159 | +- Fixed: Cache warming no longer identifies itself in a way that common firewall rule sets block, so newly published posts are warmed again on sites running 7G/8G-style protection. | |
| 160 | + | |
| 161 | += [1.3.4] – 2026-09-20 = | |
| 162 | + | |
| 163 | +**Consent-manager scripts marked late are now always left alone, below-fold sections skip rendering work until they are needed, and xSpeed's MCP server shares a site cleanly with other MCP plugins.** | |
| 164 | + | |
| 165 | +Optimization: | |
| 166 | +- New: Below-fold sections are rendered lazily with content-visibility: auto, so the browser skips their layout and paint work until they scroll into view. | |
| 167 | +- New: Block-editor stylesheets are stripped from anonymous frontend pages that do not use any blocks. | |
| 168 | +- Fixed: Scripts that another plugin marks data-no-optimize or data-no-minify late — as consent managers such as Borlabs Cookie do — are restored to their original URL and left alone by minify, defer and delay, however late the marker is stamped. | |
| 169 | + | |
| 170 | +AI / MCP: | |
| 171 | +- Improved: The AI & agents screen now leads with the MCP server and says what each of its tools does, with descriptions shown in full. | |
| 172 | +- Improved: An assistant already connected over OAuth may ask for approval once more after updating — nothing needs re-entering, and read-only connections stay read-only. | |
| 173 | +- Fixed: An AI assistant can now connect to xSpeed and to another MCP plugin on the same site. xSpeed's OAuth details moved to an address of their own under /xspeed/mcp, and the site-wide address is handed over as soon as another plugin asks for it — where nothing else wants it, xSpeed keeps answering there. | |
| 174 | + | |
| 175 | +Dashboard & Admin UX: | |
| 176 | +- Fixed: Buttons can carry a border and always show keyboard focus, and the Cloudflare Dev-mode controls use proper button styling. | |
| 177 | + | |
| 178 | += [1.3.3] – 2026-09-16 = | |
| 179 | + | |
| 180 | +**Consent gets a dashboard home, the cache engine learns to leave non-HTML alone, and uncacheable pages now tell the CDN so.** | |
| 181 | + | |
| 182 | +Privacy & Analytics: | |
| 183 | +- New: A "Privacy & usage data" panel to view and withdraw usage-analytics consent any time, with a matching wp xspeed privacy command. | |
| 184 | +- Improved: The setup wizard's analytics consent now defaults to off and is only ever an explicit opt-in. | |
| 185 | + | |
| 186 | +Caching: | |
| 187 | +- Fixed: WordPress's virtual robots.txt (and favicon) is no longer cached or minified, so every directive and newline reaches crawlers intact. | |
| 188 | +- Improved: /robots.txt joined the default cache exclusions, and the sitemap pattern now matches sitemaps.xml too — existing installs keep their working exclusion through the rename. | |
| 189 | + | |
| 190 | +Cloudflare & CDN: | |
| 191 | +- New: A page xSpeed refuses to cache now sends no-store edge headers, so a CDN never freezes a half-optimized or excluded page. | |
| 192 | +- Fixed: The deferred Cloudflare purge batch is bounded, cleared on deactivation, and says so when a purge is refused. | |
| 193 | + | |
| 194 | +Optimization: | |
| 195 | +- Fixed: Scripts marked data-no-optimize or data-no-minify are left completely alone by minify, defer and delay — consent-manager configurations always ship current. | |
| 196 | +- Fixed: xSpeed's own scripts are never deferred or delayed by its own optimizer. | |
| 197 | +- Fixed: The Conservative preset now switches LCP preload and preconnect off, matching its "page cache + GZIP only" promise. | |
| 198 | + | |
| 199 | +Dashboard & Admin UX: | |
| 200 | +- Improved: Preload now reports what actually happened — how many pages are warming, and the server's reason when a crawl cannot start. | |
| 201 | + | |
| 202 | +Reliability: | |
| 203 | +- Improved: Uninstall now removes all usage-tracking state, the scheduled send, and every leftover option row. | |
| 204 | + | |
| 5 | 205 | = [1.3.2] – 2026-09-15 = |
| 6 | 206 | |
| 7 | 207 | **Purging is now a contract other caches can join: clearing xSpeed's page cache also invalidates LiteSpeed Cache and the host's nginx FastCGI cache, and every purge is scoped to exactly the site and pages it was asked for — including on multisite.** |
| 8 | 208 | |