v0.33.0 - August 19, 2026
The long-view release. Overview still shows the recent pulse; a new Stats page is where you go to read the year: ranges up to twelve months, a custom window every analytics provider can answer, and breakdowns across the whole range, from top pages and referrers everywhere to countries, devices and search terms where the provider tracks them. Gift cards from three WooCommerce plugins share one Commerce inbox, and products and coupons now wear the same filter bar orders already had. Role defaults let a site choose the admin experience for each role without erasing anyone's saved preference, installed languages become visible and removable after years of silent accumulation, and Structure joins the rest of Minn in answering a right-click. Beneath the new surfaces, an outside security review walked the whole plugin end to end and everything it found is fixed in this release, while the Minn bar learned to hold its shape on sites with strong-willed stylesheets.
Added
- A Stats page for digging into traffic history. The Overview card shows the recent pulse; its new Open stats link (also the View traffic stats command in the palette) opens a dedicated page with ranges up to twelve months, including a custom date range: pick any window inside the last year, or one-click it with This month, Last month, This year and Last year, and every provider answers, because Minn slices the window out of the provider's own daily numbers. Switching ranges keeps the page steady; only the chart area waits. Visitor and pageview totals sit above a full-width chart, bars group by day, week or month to fit the range, and clicking a bar opens its top pages and referrers, the same drill-down the Overview chart has. Below the chart, breakdown panels cover the whole selected range: top pages and referrers from every analytics plugin Minn already reads, with richer dimensions where the provider tracks them (Matomo adds countries, devices and site searches; Jetpack Stats adds countries, search terms and outbound clicks). Plugins can feed the panels through a new
minn_admin_traffic_reportfilter. Everything rides the analytics plugin already on the site, and roles without reporting permission see a plain explanation instead of numbers. - A Gift cards surface, now a family. YITH WooCommerce Gift Cards (free and premium) is joined by official WooCommerce Gift Cards and PW WooCommerce Gift Cards (free and Pro). Same Commerce nav item, a provider switcher when more than one is active. Every provider lists cards with the Orders filter bar, leads with the outstanding balance the store still owes (expired cards are not counted), and opens a card to enable or disable, change the balance, or resend the email. The code copies with one click. Add gift card issues one by hand through each plugin's own generator, and the toast names the code it created. Product amounts, bulk generation, CSV, PDF and QR stay in the plugin.
- Installed languages, and a way to remove one. Extensions → Translations now lists every language whose files are on this site, not only the ones with an update waiting. Each language shows its locale, how many WordPress, plugin and theme translations it carries, and how many are waiting to update. Languages nothing uses get a Remove action that deletes their translation files and stops the downloads; WordPress otherwise keeps every installed language current forever, with no way to remove one, so a language tried once months ago is still being downloaded today. The site language and any language a user has personally chosen cannot be removed and say which of the two is holding them. Removing is not permanent: WordPress reinstalls a language the moment it is selected again.
- Role defaults: choose the admin experience by role. Users gains a Role defaults tab (administrators only) with two policies per role: what happens after sign-in (person chooses, or always open Minn) and which toolbar the role gets on the public site (person chooses, the Minn bar, the WordPress toolbar, or none). The controls use the same searchable dropdown as the rest of Minn. Enforced settings replace the matching switches on Your profile with a short locked note that says why. Enforcement is an overlay, never a write: changing a policy does not erase anyone's saved preference, and a role returned to "Person chooses" hands each person their previous choice back. Roles that cannot open Minn are marked honestly and are never offered a Minn policy.
- Leaving Elementor or Brizy opens Minn when it is the default admin. Elementor's hamburger still says Exit to WordPress, and Brizy's more menu still says Go to Dashboard. When Minn is the default admin, both items open Minn's front door instead of a wp-admin screen. People who have not opted in keep WordPress's destination.
Improved
- Products and coupons wear the orders filter bar. The two product tab strips (status and stock) and the coupon strip are gone. Status is the dropdown, one at a time because that is what WooCommerce accepts. Products add stock, category, tag, type, featured and on sale; coupons add a date window. Every filter is a native collection parameter and lives in the address, so a filtered list can be reloaded or pasted. Brand, price range and coupon discount type stay out: WooCommerce's collections cannot filter on them. Low stock is the store's own low-stock lookup, not a stock status. Product search matches the name or the SKU, not the name alone. Creating a product from the list now offers Open full page on the quick view, the same doorway an order already has.
- Right-click comes to Structure. Post type and taxonomy rows answer a right-click the way the rest of Minn does: open the definition, jump to that type's content, start a new item, manage a taxonomy's terms, and remove an editable definition. Entries only appear where they can actually work, so a type hidden from Minn offers no content shortcuts. Removing a definition now asks with Minn's own confirmation dialog, which spells out that existing content and terms stay in the database.
- A calmer order page header. The row of seven buttons is now two: Refund stays inline, and sending an email, copying the payment URL, the PDF documents and the WooCommerce link live behind a More menu. On a phone the back button takes its own row instead of squeezing the order title into a sliver. Two small blemishes went with it: the copy-shipping-address button no longer shows its hint twice, and a still-loading order no longer flashes an empty status chip beside its title.
- A quieter description for the Minn admin bar switch. The profile explanation shrank from a paragraph to one sentence, and the shorter text ships already translated in all twenty-four languages.
- The Playground demo already has Minn as the default admin. The signed-in admin lands with "Minn is the default admin" and "Minn admin bar on the site" turned on, so a later sign-in returns to Minn and the public site shows the Minn bar.
- Simple History's last-event time follows UTC. The status card used to read Simple History's stored GMT date as if it were the site timezone, so a Playground site set to America/Chicago showed "5 hours ago" for an event the list itself called "just now".
Fixed
- WP-CLI no longer dies while plugins load. A filter that points Choose Menu at Minn called a login helper before WordPress had loaded it, so any plugin that built an admin URL from its constructor (WPMU DEV Dashboard is the one that came up) crashed the whole command line. The rewrite now waits until those helpers exist, and the command line and cron skip it.
- The Minn bar stays out of page builders. Elementor's preview canvas (and the other front-end builders Minn already knows) hide the classic admin bar. The Minn bar is a replacement for that bar, so it now stays off those canvases too instead of floating over the editor. Brizy's editor iframe uses its own
is-editor-iframeflag, which is now recognised the same way. - The Minn bar sits above a theme's own header. Divi's fixed header (and other themes that use the same 99999 rung as the classic admin bar) was painting over the bar, so the homepage looked like the bar was missing. The bar now stacks above that chrome.
- Choose Menu on the public site opens Minn. When Minn is the default admin, a theme's empty-menu fallback (Beaver Builder's Choose Menu is the one that came up) goes to Minn's Menus screen instead of wp-admin. The classic menus screen is unchanged.
- Low stock still applies when you search. Typing in the products search used to drop the Low stock chip's meaning: the list became a plain name search and an in-stock product could appear while the chip stayed on. Search now runs inside the low-stock set. The same path remaps a low variation to its parent, because this list only opens catalog products, and combined filters such as Low stock + Featured ask WooCommerce for those parent ids.
- A gift card filter survives leaving the page. Coming back from another list used to keep the chips and lose the address, and a pasted search in the URL never reached the first request. The bar now writes the filters back on paint, sends a pasted search on the first load, and ignores a stale response when the filters change mid-flight.
- The products filter menu stays next to Add filter. Opening Featured (or any Yes/No filter) right after a list load used to pin the menu in the top-left corner, because the button it hung on had been replaced. It now finds the live button, and a list rewrite closes a stale menu instead of leaving it behind.
- A gift card switch has to say which way it goes. A request to enable or disable a card that left the field out was read as a disable, so a truncated or malformed request could quietly take a live card out of circulation. All three gift card plugins now refuse that request and say what is missing. Listing gift cards also stopped writing a warning into the debug log on every load.
- A gift card cannot be turned on by the word "false". Enable and disable go through the same boolean WordPress uses everywhere else, so the string "false" now means off. A typed code has to be plain text, and an amount larger than a real store card is refused rather than stored.
- A security review of the whole plugin, and everything it found. An outside audit went through Minn end to end. Nothing it found could be reached by a visitor who is not signed in, and nothing let anyone sign in who could not already. What it did find were places where Minn showed or allowed a little more than the plugin or WordPress screen it stands in for. All of it is fixed below.
- The site's admin bar keeps site posture to administrators. The bar on the public site named which coming soon, maintenance or password plugin the site runs, and said when the site was a staging copy, to anyone who can write posts. Minn already had a rule for that detail elsewhere, and the bar now follows it.
- A site on a network sees only the themes it may use. The theme list showed every theme installed on the whole network, with versions, and which ones the network had withheld from that site. It now shows what the site's own Appearance screen shows.
- Moving a site between networks asks about both of them. The move checked that the person administers the network the site is going to, never the one it is leaving, so on an installation with several networks one of them could take a site out of another, along with its content, users and settings. Deleting a network and moving a site also read their target from whichever part of the request answered first, so a stray value in the body could act on a different network than the one the address and the confirmation named. Both now read the address only.
- Booking staff limits are honoured in full. LatePoint restricts a member of staff by agent, by location and by service. Minn applied only the first, so a person scoped to one location could see, approve and cancel appointments outside it, which sends the customer an email. Amelia grants seeing and changing other people's appointments separately, and Minn decided both from the seeing one.
- Opening a saved rich text value cannot run anything inside it. The check that cleaned a stored value named only a handful of things to remove and then re-read the cleaned copy as text, which undid the protection. Several ways of running code walked through. Tables, images, links, lists and formatting still come through exactly as saved.
- Addresses are checked wherever they are used. Typing a link, opening a page from the traffic report, and entries a plugin adds to Minn's own lists all now go through the same check, which allows ordinary web addresses and refuses anything that would run code or point off the site.
- Every custom field on an options page follows the same rule. Values saved on an options page print across the whole site, and the rule that strips unsafe markup reached only the fields at the top of the page, not the ones inside a repeater or a section. A web address is now stored the way it was checked, and importing a field group cannot overwrite an unrelated page.
- Guards that quietly did nothing now work. On a site with file editing turned off, the control that switches a code snippet on was withdrawn by comparing the button's wording, so it did nothing at all in any language other than English, and it never covered the same control in the bulk menu. Saving a snippet also always turned its insert method on, so a snippet meant to run only where its shortcode appears started running everywhere the next time anyone renamed it. The stored insert method is now carried through, and switching it is a field people can see rather than something a save decides for them.
- The Minn bar keeps its shape on sites with hand-written link styles. A site whose custom CSS draws a border under every link and changes how links lay out was redrawing the bar's menus: a line under every item, icons stacked above their labels, and the site's letter spacing leaking into the bar's text. The bar now states its own layout, underline and spacing rules firmly enough that the site's styling cannot reach them.
- Your picture shows on the Minn bar even when the site hides avatars. The Discussion setting that hides avatars in comments also blanked the bar's account button. The bar is part of Minn, not the page, so it now shows your picture the same way the rest of the app does.
- Shared server logs are left alone. Where the debug log is configured to a file outside the site, which on shared hosting is often a log the whole server writes to, one of the two ways to reach it printed the full path and would empty it. Both now refuse.
- Smaller boundaries tightened. The System page no longer reports network wide facts to a single site's administrator. Deleting expired saved values on a network now asks a network administrator before touching values every site shares. The content feed no longer says whether a published post has unsaved edits, or who is editing it, to people who cannot edit it. Adding an existing account no longer answers differently for a network administrator's address, which had let someone test addresses to find them. The people picker no longer lists the site's users before anything is typed. A pasted licence key that fails to activate can no longer lose the working key it replaced. And a workaround for one page builder no longer lets any visitor quiet what the site writes to its log.