The follow-through release. Most of what is here was already half built: a chart that drew fourteen days and gave you bars you could point at but not click, a search box you could fill but not empty, a history panel every kind of content had except the one whose changes are hardest to undo. Sixteen charts open the day you click now, across every mail and forms provider a site might run. Every list search clears with one button. And a template keeps its history, with any version readable against what is on screen and one click to put it back.
Duplicator rewrote itself. Its fifth version moved the tables and dropped the classes Minn reads, so the Backups page quietly lost its Duplicator provider on any site that updated, with nothing to say why. It is back, reading the new plugin properly and still reading the old one, and building a backup now runs through the request service Duplicator 5.0 added, so the progress you watch is the plugin's own.
Then two security passes, and the same lesson from both. The first went over v0.38.0 and found that its fixes were real but several had stopped one file short of the next place the same mistake lived. The second went over this release before it shipped and found nine more of that shape, one of them a single link short of a fix made earlier in this very cycle. Both rounds are closed here, and each fix ships with a check that fails on the code before it.
Added
- The Gravity SMTP email log can be searched and filtered by source. Type an address, a subject, a sending plugin or a phrase from the body and the list narrows, the same fields Gravity SMTP's own log searches. A Source filter sits beside the Sent and Failed tabs (a dropdown once the origin list would overflow), and Source and Service columns show where each mail came from. Search, source, status tabs and a clicked chart bar combine. A × inside the field (or Escape) clears the query; Clear wipes the query, the source, the status tab and the day chip together. Typing is not interrupted when results refresh.
- WP Mail SMTP's page catches up with the others. The free plugin keeps no email log, so its page in Minn lists the debug events it does keep: delivery errors, and sends too once verbose logging is on. It was the one mail page with no search, no summary and no chart. It now opens with the same card its siblings have (errors in the last thirty days, which mailer is configured, how many events are logged, and whether debug logging is on, which is the usual reason a healthy site's list looks empty), draws the same fourteen-day chart with the same clickable bars, and has a search that matches what WP Mail SMTP's own screen matches.
- A bar on the entries chart opens that day's entries. Every forms card has drawn fourteen days of submissions for a while, and the bars did nothing. Clicking one now narrows the entries beneath it to that day, with a chip naming the day and clearing it, exactly as the email log does. All ten forms providers have it: Contact Form 7 (with Flamingo), Contact Form CFDB7, Elementor, Everest Forms, Fluent Forms, Formidable, Forminator, Ninja Forms, SureForms and WPForms. Each reads the clock its own plugin stores its submissions in, so a bar picks the day you meant: a submission recorded at two in the morning UTC belongs to the previous evening where the site actually is, and that is the bar that finds it.
- A bar on the email chart opens that day's log. The status card on the Email page has drawn fourteen days of sent and failed counts for a while, and a bar you could point at but not use. Clicking one now narrows the log beneath it to that day, with a chip beside the Sent and Failed tabs naming the day and clearing it, and the same bar again widens the list back. The narrowing combines with the tabs, so Failed plus a bar is that day's failures. Every mail provider has it: Gravity SMTP, FluentSMTP, Post SMTP, WP Mail Logging, Site Mailer and SureMails. Each one reads the clock its own plugin stores its timestamps in, so a bar picks the day you meant whichever provider you run. Any plugin whose surface draws a chart can add it with one line.
- The email chart counts every email, not only the delivered ones. Sandboxed and filtered sends stayed off the chart, so a site in test mode saw fourteen empty days over a full log, and a bar's numbers did not match the day's list. The soft bar is now everything logged that day, with the tip breaking out Sent, Failed, Sandboxed and Filtered, and the solid bar still means sent.
- Duplicator 5.0 keeps its place in Backups. Duplicator's fifth version rebuilt the plugin underneath: the classes Minn read are gone and its backups moved to new tables. Minn's Duplicator provider quietly disappeared from Backups on any site that updated, with nothing to say why. It is back, and it reads the new plugin properly: your backups list with their real sizes and dates, downloads for the archive and the installer, delete through Duplicator's own removal, and Build a package now runs through the request service Duplicator 5.0 added, so the progress you see is its own ("Exporting database tables", "Compressing files and folders") and Stop is its own cancellation. Sites still on Duplicator 1.5 are unaffected and keep working exactly as before. Who made a backup is no longer shown, because 5.0 stopped recording it.
- A template keeps its history, and you can go back. Templates and template parts open in Minn's own editor, but the History panel every post has was missing from theirs, so the only record of what a template used to look like was in the Site Editor. A template this site has saved its own copy of now shows History in the sidebar: every saved version, who saved it, when, and what changed, with one click to see a version side by side against what is on screen and another to put it back. A template still coming straight from the theme has no history to show and says nothing, as before.
- Every list search clears with one click. A small × appears inside the search box as soon as you type, and clicking it (or pressing Escape in the box) empties the search and brings the full list back with the cursor still in the field. Content, Media, Users, Customers, Extensions, the database tables and every plugin's own list all have it. Searching Users no longer blanks the list while it reloads, either: the rows stay put and dim, the way the other lists already behaved.
Fixed
- The email chart's days are your days. The chart bucketed sends by the UTC calendar while the Date column beside it showed your site's time, so an evening send sat on tomorrow's bar and a clicked bar listed rows dated the day before. Bars now follow the site's timezone, and a bar's rows carry its date.
- The block editor shortcut works with the key Windows has. The WordPress button in the sidebar opens the post you are editing in the block editor when you hold a modifier while clicking, but the hint named only the Mac key, and on Windows and Linux Ctrl-click did nothing. Ctrl-click opens it now, the hint names Alt and Ctrl on those systems, and the keyboard help says which key stands in for which.
- Pasted blocks arrive inert like everything else. Content a plugin or a pattern puts into the editor is parked on the way in and woken up on save, so nothing in stored markup runs while it is being placed. Inserting from the slash menu and the block browser learned that last release; pasting did not, so markup copied from somewhere else could run in the editor as the person who pasted it. It cannot now.
- JetEngine meta boxes hidden from a role stay hidden. A meta box can be restricted to particular roles, and JetEngine's own screen then neither shows nor saves its fields. Minn honoured the settings that limit a box to certain posts but not the ones that limit it to certain people, so a role the site had withheld a box from could read and write those fields anyway.
- A picture is only attached by someone allowed to attach it. JetEngine image and gallery fields took any id they were given and handed back the file's address, which let someone read the location of media they could not otherwise see, and publish it. The three questions the rest of the app asks about an incoming picture now live in one place that every field type asks.
- A refused value no longer erases a stored one. Saving a JetEngine panel treated "this value cannot be accepted" and "this field was emptied" as the same answer, so a whole-panel save could wipe a value the person saving had never touched: a choice whose options were edited later, a number a form wrote in words, a picture since deleted.
- A field you cannot see is not blanked by saving the page. WP Job Manager can hide an applicant's address and the salary from some roles. Reading learned that last release, but the panel still drew the field with nothing in it, so an ordinary save wrote the empty box back over the real value.
- Backups download through Minn's own door, all of them. All-in-One WP Migration was the exception: its Download handed out a link to the archive that works for anyone who has it, or one carrying the site's own secret key. The link an export hands you the moment it finishes did the same. Both go through the same nonce-checked door as every other provider now.
- A booking list is never shown unscoped, and this time everywhere. JetBooking showed every vendor's bookings when it could not work out whose they were. Not knowing is not the same as there being none.
- What a delete confirms is what a delete does. Forty-seven actions that remove something took the id from the path shown in the confirmation rather than one that could be supplied alongside it.
- Maintenance mode holds the side doors shut for everyone it should. The holding page kept a small exception open for Minn's own background request, and that exception could be borrowed: a visitor who added the right word to the address could still post a comment or a trackback, read the bookmark list, reach XML-RPC, or open the signup and activation pages on a site that was supposed to be closed. The exception is gone. The people allowed in never needed it, and nobody else can use it.
- Deleting a Duplicator backup asks Duplicator's question. Duplicator 5.0 lets a site give someone permission to see backups without permission to make or remove them. Minn's Delete asked only for the first, so a person who could look at the backup list could also erase a backup. Delete now requires the same permission Duplicator's own screen requires, and the button only appears for someone who holds it.
- The WPMU DEV connection stays with the people the Dashboard entrusts it to. WPMU DEV's Dashboard lets a site limit which administrators may manage the Hub connection. Minn let any administrator connect, disconnect or re-sync it. Those controls now appear only for an administrator the Dashboard itself allows. And a mistyped key no longer disconnects a working site: the previous key and membership are put back when the Hub rejects the new one, which is what the Dashboard does.
- A custom field written from Minn is filtered the way ACF filters it. ACF strips scripts and unsafe markup from every field an author saves unless the site trusts that person with raw HTML. Minn applied that rule to site-wide option fields but not to the fields on a post, so an author could store a script in a text field. Every field type on every scope now follows ACF's rule.
- Pods fields restricted to a role stay restricted. Pods can limit a field, or a whole group, to administrators, to certain roles or capabilities, or to logged-in users, and its own screen neither shows nor saves such a field to anyone else. Minn showed and saved them to whoever could edit the post. The same restriction now applies in Minn: a withheld field is absent from the panel, not readable, and not writable.
- Two more Perfmatters fields are treated as code. The lazy-loading threshold is placed inside a script on every front-end page, and the login message is shown as-is on the disabled-login screen. Neither was on Minn's list of fields that reach the page unescaped, so an administrator the site does not trust with raw HTML could still store script in them. Both are on the list now.
- OttoKit's request payloads no longer show the connection token. Retrying an outgoing request stores its headers alongside it, and those headers carry the token that authorises the site to OttoKit. OttoKit's own screen leaves the headers out when it displays a request; Minn's did not. It does now.
- Granting network administrator asks what WordPress asks. WordPress only offers the super-admin checkbox to someone who may edit that user, and never on their own profile. Minn checked the network setting permission alone, so on a network whose roles split those permissions a person could promote themself. Both of WordPress's conditions apply now.
- The Playground demo boots again. Code Snippets 3.10 moved the class the demo uses to seed its example snippets, so the one-click Playground link died on its last step with a critical error instead of opening Minn. The seeding step now finds the class where either version keeps it, and the demo was run end to end against the current plugin.
- The changelog modal reads wrapped text as prose. A release note written across several source lines rendered as one short paragraph per line, with a blank gap after each. The modal now joins wrapped lines into the paragraph or bullet they belong to, the way any Markdown reader does, so the shipped v0.38.0 notes read normally on older builds too.
- Redirection's first-run setup is back. Redirection 5.10 moved its database installer to a new home inside the plugin, and Minn's Redirects page went looking in the old one, so a fresh install showed an empty list instead of the one-time setup card and every add failed until you visited Redirection's own wizard. The card is back on 5.10 and still works on older builds.
- Smaller repairs. Duplicator, Bricks page and template settings, Bricks global classes, JetAppointments' detail and the AI1WM surface each ask their own plugin's question rather than restating an answer. A duplicated Elementor template goes through Elementor's own markup filter. JetAppointments shows the fields its own screen shows rather than everything stored on a booking. Meta Box and Pods hold a typed address to the same schemes as every other link. Design-library images stop matching a different picture whose name merely starts the same. SEO values stop reading back on a content type the plugin was switched off for, and SiteSEO honours that switch. The activity chart and the store cards count only what their reader may see. Independent Analytics stops naming itself on a site that renamed it. Entry charts read a total per day instead of every entry, so a spam wave cannot take the page down. And the database pages recognise a neighbouring install even when it is missing a table.