The full-depth release. The SEO panel stops summarizing and starts covering: every supported SEO plugin now edits its real per-post surface from Minn, robots directives to social cards to schema, each in its own vocabulary and each behind its own plugin's permissions, with a live search-result preview on top. On the public site the bar takes its quiet streak to its natural end. Nothing shows at all until your cursor reaches the corner, where two small accent strokes mark the spot and the complete bar arrives in one motion, and hopping between the site and the admin lands with the bar already open.
The rest came from people writing in. Paste a video link without it becoming a player, move a block with the block editor's own keyboard chords, filter Media down to your own uploads. A handful of editor bugs are gone: deleting a bullet under an embed no longer takes the embed with it, a linked image opens one panel instead of two, and choice fields in the content dialog finally look like the app around them. A full security review walked every surface again, and everything it flagged worth fixing is fixed here.
Added
- The whole Rank Math metabox, in the SEO panel. The panel used to stop at title, description and keyword; the rest of what Rank Math manages per post lived only in wp-admin. It is all here now: search indexing (index, no index, nofollow, no archive, no image index, no snippet) with the same inherit-the-post-type-default behaviour as their metabox, the max snippet, video preview and image preview limits, the canonical URL, pillar content, and the full social split, with Facebook title, description and image, and Twitter fields that appear when the card stops borrowing from Facebook, card type included. A Schema row shows what schema the post actually emits; building schema stays in Rank Math's generator, one click away. Clearing any field restores the site-wide default rather than storing an empty value, exactly as Rank Math's own editor does. Setting a Facebook image also no longer quietly switches Twitter back to borrowing it.
- Yoast reaches the same depth. The panel maps Yoast's whole per-post surface: search indexing and the robots directives, canonical URL, cornerstone content, Facebook and X titles, descriptions and images (each network appears only while its site-wide switch is on), and the schema page and article types, with the article select hidden on pages the way Yoast hides it. Yoast's own permission model carries over exactly: on a site where advanced metadata editing is reserved (Yoast's default), an author sees no robots or canonical fields, and the server ignores those values from anyone the vendor's rule excludes. Rank Math's groups follow the same discipline, appearing per person according to its per-tab capabilities and setup mode.
- AIOSEO too, in its own shape. AIOSEO keeps one "use default settings" switch in front of its robots directives rather than a per-directive inherit, and the panel mirrors that: flip the switch off and the noindex, nofollow, archive, image and snippet directives appear with the snippet, video and image preview limits. Canonical URL, pillar content, the Facebook fields with a custom image, and the X card that borrows from Facebook until told otherwise are all editable, every value flowing through AIOSEO's own post model so its table, sanitizers and caches behave exactly as if their screen had saved it. The Schema row reads what their generator built, or the post type's default when nothing was, and each group appears only for people AIOSEO's own access rules allow.
- SEOPress and SiteSEO, as the pair they are. One provider covers both (SiteSEO is the SEOPress fork with its own meta prefix): the robots flags, canonical URL, and the full Facebook and X fields including images, stored exactly the way their own metaboxes store them, image dimensions and all. SiteSEO additionally keeps the per-post no-archive flag SEOPress dropped, and only the fork offers it.
- SureRank and Squirrly round out the set. SureRank gains its robots flags, the Facebook fields, and the X card that borrows from Facebook until switched off, all flowing through SureRank's own grouped storage with the same careful clearing the panel already used for its titles (an emptied field is removed rather than filled with the site template). Squirrly gains no-index and nofollow, canonical URL, and the Facebook and X titles and descriptions, every value moving through Squirrly's own API rather than its serialized table. With these two, every supported SEO plugin now edits its real per-post depth from the panel, each in its own vocabulary and none pretending to fields its plugin does not have.
- A search-result preview at the top of the SEO panel. The panel opens on what this post will look like in Google: address, title and description, resolved through Rank Math's own template variables, so a post with no custom title shows the real effective one, template and all. It follows your typing live, resolves tokens such as %sitename% as you write them, and falls back to the site default the moment a field is cleared. The SEO title and meta description also carry length counters (60 and 160), which turn red past the limit. Every SEO plugin gets the preview; Rank Math's is exact, the others approximate from their stored values until their adapters deepen the same way.
- A Mine filter in Media. Next to Unattached there is now a Mine toggle that narrows the library to files you uploaded, and it remembers your choice between visits. On a site with several writers this is the difference between scrolling everyone's screenshots and seeing your own work. It is a view filter, not a wall: WordPress's own permission model still decides who can access what, and Minn does not pretend otherwise.
- The front-end bar disappears entirely until you reach for it. On desktop screens the corner bar no longer rests as a visible mark: a healthy public page shows no admin chrome at all, and moving your cursor into the top-left corner brings out the complete bar in one motion, with no icon-only stop along the way. The spot itself keeps working while invisible, so a blind click on the corner still opens Minn, and hopping between the site and the admin by clicking that same corner lands with the bar already open each time. Phones and narrow windows keep the visible launcher, and any status worth knowing about (maintenance mode, coming soon, a password gate) keeps the bar visible too: chrome on screen means something needs your attention. While the bar is hidden, two small angled strokes in your accent color rest in the corner, the way a window wears a resize grip, so the spot still whispers that something lives there.
- Move a block with the keyboard. Ctrl+Shift+Alt+T moves the paragraph, heading, list or protected block under your cursor up one position, and Ctrl+Shift+Alt+Y moves it down (Cmd on a Mac). They are the block editor's own combinations, so the habit carries straight over, and pressing the opposite one puts the block back. Both are listed in the help dialog's Keyboard shortcuts.
Fixed
-
Maintenance mode holds the whole site back. Turning maintenance mode on put a holding page in front of visitors, but the site's data endpoints kept answering, so every published post, page and file was still readable by anyone who asked for it directly. That is the same content the front page was already showing on a live site, and it is the wrong answer entirely on a site being staged before launch. Everything is held back now. Minn itself stays reachable, and so does anyone who can edit posts.
-
The database browser stays inside this install. On hosting that puts several sites in one database, a neighbouring install whose table names begin with this one's could be opened from the browser, including its users table. The browser now works out which tables belong to a neighbour and leaves them alone, while a plugin's own table that happens to be named similarly stays where it belongs.
-
A site's decision to hide the toolbar is respected. Turning the admin toolbar off for everybody is how a site says it wants no admin chrome on public pages, and the front-end bar was appearing anyway for anyone who had opted into it.
-
Seven plugins are asked the question they ask themselves. Post SMTP, Wordfence, WPvivid, BackWPup, Asset CleanUp, WP Mail Logging and Gravity Forms each decide who reaches their screens in their own way, and Minn had been standing in with a general settings permission instead. A role built to manage settings without being an administrator could reach message bodies, login records, backups and the full forms roster that those plugins would not have shown them. Administrators are unaffected.
-
A backup action names the backup you confirmed. Six backup surfaces read the item to act on in a way that let a value elsewhere in the request take over, so the confirmation you read could name one archive while the request removed another.
-
Fields say only what they are for. A Forminator entry row was printing the server's own folder layout beside an uploaded file's address, a licence could be credited to a component that did not own it, and a linked venue or organiser could be read back by hand even when the picker would not have offered it.
-
A redirect deletion only ever deletes a redirect. Removing a Safe Redirect Manager rule went through a helper that plugin has never actually shipped, so it always fell through to a permanent delete of whatever post carried that id, with nothing checking that the id named a redirect. A stray id could take a page or an order with it, past the trash, with no way back. The route now confirms its target first and refuses anything that is not a redirect, and it clears their cache afterwards the way their own screen does. Redirects also answer to the capability Safe Redirect Manager itself uses rather than a general settings one, so locking them down works and handing them to an editor works.
-
Entry files keep Gravity Forms' protected links. The entries list handed back each uploaded file's real location. That address needs no login, never expires, and gives away the folder every other file on that form sits in, which is the one thing keeping them private. The list now uses the same protected link Gravity Forms uses on its own entry screens, as the entry detail already did.
-
Each SEO plugin's own permission is asked before its fields are written. Four fields were offered to people their SEO plugin does not offer them to: SureRank reserves all of its per-post fields to administrators, Yoast withholds the schema type from the same people it withholds the canonical from, SEOPress files the target keyword under a second, separately controlled area, and All in One SEO keeps cornerstone on its Advanced tab. Each now answers to the rule its own plugin applies.
-
The media an ACF or ACPT image field points at is authorized. Those fields accepted any attachment id, so someone who cannot upload anything could still point a field at a file that was not theirs and publish it. They now ask the same questions the SEO panel asks of a social image.
-
A surface disappears when its plugin has taken it away. Some plugins decide who reaches a screen with a setting rather than a permission, and enforce it by not building the screen at all, which no permission check can see. Six surfaces stayed up after their plugin had withdrawn them: WPCode's snippet manager on a site limited to header and footer scripts, ACPT's option pages with the feature switched off or the licence lapsed, AnalyticsWP and Burst where the operator had narrowed access, Simple History while it was deliberately hidden, and All in One Security where its permission had been filtered. Each now asks its plugin the same question its plugin asks.
-
A duplicated or pasted block is handled like every other stored block. Opening a post neutralizes anything in the saved markup that could run before it reaches the page. Duplicating a block, or copying one within a post, skipped that step, so the copy was treated differently from the original sitting next to it. Both now take the same path, and the saved markup is unchanged either way.
-
Paste a video link without embedding it. Pasting a YouTube or other video link into an empty line turns it into an embed, which is usually right and sometimes exactly wrong: sharing several links should not fill the post with players. Paste without formatting (Ctrl+Shift+V, or Cmd+Shift+V on a Mac) now does what it does everywhere else: the link lands as plain text, nothing embeds, and copied markup or rich content pastes plain the same way.
-
Choice fields in the Edit content dialog match the rest of Minn. A block setting with a fixed set of options (a stat card's color, an alignment) rendered as the browser's own dropdown, which ignores dark mode and looks nothing like the app. Those fields now use the same themed picker as everywhere else, typing filters the options, and picking one can no longer accidentally close the dialog.
-
Clicking a linked image opens one panel, not two. An image with a link on it answered a click with both the image panel and the link popover at once, the same address editable in two places. The image panel is the one that owns an image's link, and it is now the only one that opens; link text elsewhere in a post keeps its popover.
-
Deleting a bullet under a video no longer deletes the video. With a bulleted list sitting directly below an embed, pressing Backspace on a bullet could mark the embed above for deletion and then remove it. The editor now leaves list deletion to the browser, which handles it safely: the bullet dissolves into a plain line and the embed is never touched.
-
Forms no longer needs Gravity Forms' REST API switch. The Forms surface used to appear only on sites that had turned on Forms → Settings → REST API, a switch most sites never touch, so a site could run Gravity Forms for years and never see its entries in Minn. Every request now goes through Minn's own routes over Gravity Forms' PHP API, which is always available, so the surface simply works, with their REST API on or off, behaving identically either way. The workflow endpoints also got stricter in the move: where their API accepts any entry property from anyone allowed to edit entries, Minn's accept exactly the three the surface uses (read, star, status).
-
The front-end bar wears your color scheme. The bar on the public site kept Minn's stock purple no matter which appearance you picked on Your profile, so a site set to Ocean or a hand-built custom palette changed identity every time you stepped out of the admin. It now follows the same saved scheme as the rest of Minn: all the named presets and a fully custom palette, in light and dark alike.
-
The phone launcher wears the same mark as the admin. On phones the front-end bar's corner tile rendered larger than the tile the admin sidebar wears, so the two views handed off between two sizes of the same mark. The tile is now identical on both sides (the tap target stays as large as before, only the visual shrank).
-
The Format picker is there on a new post. A theme that adds post formats, a Link or a Quote or a Video, only offered them on a post that had already been saved, so the choice was missing at exactly the moment you were making it. The picker is in the Settings panel from the start now, and a new post begins on the default format from Settings > Writing, the way wp-admin has always started one. Leaving that default alone keeps it: a new post used to save as Standard no matter what the picker said.