github austinginder/minn-admin v0.42.0

3 hours ago

The one-list release. Update everything now runs plugins, themes and language packs as a single batch that walks one list, and every activity log draws the same fourteen-day chart the mail and forms views already had, with a bar that narrows the list to that day. MonsterInsights, ExactMetrics and self-hosted Matomo join the Traffic chart, logged emails stop firing their senders' tracking pixels when you open them, and Rank Math redirects, Broken Link Checker, Sucuri's audit log and LatePoint event registrations all land in Minn. The cycle closes with the longest security pass yet: a full review of the release candidate found two medium issues and a set of smaller ones, and every fix was then reviewed on its own before it shipped, which turned up and closed an older way for a Contributor to plant script that ran when an administrator saved their post.

Added

  • Every activity log charts its last fourteen days, and a bar narrows the list to that day. Simple History, WP Activity Log, Stream, Activity Log (Aryo), All-In-One Security, Wordfence, Solid Security and Limit Login Attempts Reloaded all draw the same fourteen-day chart on their status card that the mail and forms views already had: events per day, with errors, high-severity events, warnings or failed logins split out where the plugin records them, and lockouts per day on the two lockout logs. Clicking a bar narrows the list beneath it to that day, a chip beside the tabs names the day and clears it, and the narrowing combines with the tabs and search. Each log is counted on the site's own calendar whatever clock the plugin stores its rows in. Simple History's list folds repeats of one event into a single row, so its bar can read higher than the rows a click shows; that is the plugin's own arithmetic.

  • Update everything means everything now, and it walks one list. Every Update everything control (the Plugins toolbar, the new one on the Themes tab, the notification panel and the palette) runs plugins, themes and language packs as a single batch behind one panel, in that order, each row ticking down the list with its old and new version; WordPress core still follows last on its own, since it owns the maintenance window. The Plugins button counts every pending update rather than plugins alone, and the Themes tab finally has a bulk button of its own. Update translations rides the same batch runner with only language packs in it.

  • Update translations runs as one batch and shows its work. The Translations tab's button now updates every pending language pack in a single request, the way Update everything handles plugins: packages are fetched side by side first, then installed one after another, and the same panel opens with a row per pack (plugin, theme or WordPress, and its language) moving from Queued through fetched, Extracting and Installing to a green tick, with a closing line of totals and timings. Hide the panel and the batch keeps running; the chip in the top bar counts it down and reopens it.

  • MonsterInsights Pro and ExactMetrics Pro licenses on the Licenses tab. The Pro builds now show their license state (plan, expiry, and whether the vendor last rejected, disabled or expired the key), and the row offers paste-to-activate, re-verify and deactivate through the plugin's own license code, so a seat freed here is freed with the vendor too.

  • MonsterInsights and ExactMetrics join the Traffic chart. The two most-installed Google Analytics plugins keep their reports on Google's side and fetch them through Awesome Motive's relay, so nothing sat in the database for Minn to read. Minn now asks the plugin's own overview report for the numbers, using the Google connection, permissions and report cache the plugin already manages: the Overview chart shows daily sessions and pageviews, the day drill-down lists top pages (with real post titles) and referrers plus an Open MonsterInsights or Open ExactMetrics link, and the Stats page adds countries and devices. Access follows the plugin's own "view reports" roles and its dashboard switch, and a freshly connected property with no data yet steps aside for another analytics plugin. Also fixed on the way: a plugin whose activation redirects wp-admin to its onboarding wizard no longer logs a browser error from Minn's background notice and link captures.

  • Self-hosted Matomo and Matomo Cloud join the Traffic chart. Minn already read the Matomo that installs inside WordPress; sites that run Matomo on their own server, or on Matomo Cloud, connect it through the Connect Matomo plugin instead, and that Matomo lives entirely off-site. Minn now reads it through Connect Matomo's own request queue, so the Overview chart, the day drill-down (top pages with real post titles, referrers, an Open Matomo link) and the Stats page breakdowns (countries, devices, site searches) all arrive in one request to the Matomo server, using the connection and token the plugin already holds. Access follows the plugin's own "display stats to" setting, and a connected Matomo with no visits yet steps aside so another analytics plugin can answer.

  • Opening a logged email no longer tells the sender you read it. Email previews in every mail log (WP Mail Logging, FluentSMTP, Post SMTP, Gravity SMTP, SureMails, Site Mailer and form notifications) used to load the message's remote images, which fires the tracking pixels many marketing and transactional emails carry. Remote images, stylesheets and fonts are now blocked by default, and a bar above the preview offers Load images when the message has any. WP Mail Logging's own "Always Load Remote Images" setting is honored.

  • WPS Hide Login shows up on the System page. A Login address row names the address the login page now answers on and where wp-login.php and wp-admin send visitors, and it warns while the plugin still uses its default /login/, which bots try right after wp-login.php.

  • Rank Math redirects and its 404 log, in Minn. Sites that use Rank Math's Redirections and 404 Monitor get a Redirects view beside the other redirect plugins: the redirect list with Active, Inactive and Trash tabs, adding and editing a redirect (Rank Math's own check refuses one that would loop back to itself), and a 404 log where Redirect… on any logged miss sends that address somewhere useful. A status card counts active redirects, redirect hits, logged 404s and the most-hit missing address.

  • Sort Simple History by event, level or date. Click a column heading in the Simple History log to sort by it, and click again to reverse. This needs Simple History 5.34 or later; sorting by anything other than date lists each event on its own rather than grouping repeats, which is how Simple History itself sorts.

  • Scrutoscope shows whether background jobs are keeping up. Its status card now lists pending and running Action Scheduler jobs and, when the oldest one is overdue, by how long and which job it is, plus a count of failed jobs with the most recent one named. A queue that has stopped draining is the usual reason WooCommerce emails, renewals and imports quietly stall.

  • SiteOrigin Page Builder and Oxygen pages are protected in the editor. Both keep the real page outside the normal content, so an edit made in Minn would never show on the site. Minn now recognizes pages built with SiteOrigin Page Builder and with Oxygen (the classic Oxygen 4 and the newer Oxygen 6), keeps their body read-only, and offers a button that opens the page in its builder. The protection holds even while the builder plugin is switched off.

  • Elementor MCP joins Agent Access. Elementor 4.3 can let AI tools such as Claude, Cursor or Codex read and edit Elementor pages. It is off by default. Minn now shows whether it is on, turns it on or off with the same switch Elementor uses, and lists the connections its setup created on every account you manage, with when and from where each was last used and a Revoke button. Novamira and Elementor MCP share one Agent Access entry with a switcher.

  • Gravity SMTP email details show the Reply-To address. Gravity SMTP 2.3.4 started keeping the Reply-To of each email it sends, and the email detail now lists it beside From, Cc and Bcc.

  • SureForms: a Forms list with views and conversion, and each entry's activity. The SureForms view gains a Forms list showing each form's entries and, once SureForms' form view tracking is switched on, its views and conversion rate, calculated exactly the way SureForms calculates them. An entry's card now ends with its activity log, which since SureForms 2.12.8 includes whether the notification email went out.

  • Export Safe Redirect Manager redirects as CSV or JSON. Safe Redirect Manager 2.3 added an export, and its status card now links it, using the plugin's own signed download so its permission check still applies.

  • LatePoint event registrations. Sites that sell LatePoint events get an Event registrations view beside Appointments: who registered for what, how many seats, upcoming or cancelled, with the customer and event in the detail. Cancel registration does exactly what LatePoint's own button does: it releases the seats and sends LatePoint's cancellation notice, and leaves the order alone.

  • Sucuri Security's audit log joins Activity Log. The events Sucuri records on the site (logins, plugin and theme changes, settings, and its own warnings) list in Minn with level tabs, search and the same fourteen-day chart as the other activity logs. Minn reads only what Sucuri keeps on the site, and the status card says when Sucuri's API service sends older events to its own servers instead.

  • Broken links under Tools. With Broken Link Checker running its standard local checker, Minn lists the links it has found broken (plus warnings, redirects and dismissed ones), shows where each appears, and fixes them in place: recheck a link, change its address everywhere it appears, remove it while keeping the text, mark it as working, or dismiss it. Access follows Broken Link Checker's own setting for who may see its links screen.

Fixed

  • All-day events show as all-day again. The Events Calendar now records an all-day event differently, and Minn's event panel read every all-day event as a timed one, so the switch looked off after saving. Minn now asks The Events Calendar itself.

  • SEOPress and SiteSEO role restrictions hold on older plugin versions. Both let you block chosen roles from the SEO box. On SEOPress versions before 10.1.1, and on older SiteSEO, Minn could not find the plugin's check and let every role edit SEO titles, descriptions and noindex on their own posts. Minn now reads the same setting directly, so a blocked role stays blocked.

  • Custom CSS & JS snippets follow the plugin's own per-snippet permissions. A role given only access to the snippet list could switch off or permanently delete other people's snippets through Minn, where the plugin's own screen also asks for edit, delete and publish rights on that snippet. Minn now asks for the same rights.

  • The database browser's hidden password and token columns can no longer be guessed through search or sort. Password hashes, reset keys, login session tokens and WooCommerce API secrets were hidden in the rows, but searching or sorting on those columns still answered questions about what they held, enough to rebuild a value a character at a time. Those columns can no longer be searched, and sorting by them keeps the table's normal order.

  • Editing a WooCommerce API key's description no longer hands the key to you. Store settings sent only the fields you changed, and a key edited that way was reassigned to whoever edited it and dropped to read-only access, so an integration using it lost write access and its credentials started acting as you. An edit now changes only what you changed.

  • Saving a payment method in Store settings no longer erases its other settings or your bank accounts. WooCommerce re-saves every field of a payment method on each save, so the fields Minn does not show were being cleared, and saving Direct bank transfer deleted every bank account the store lists on thank-you pages and emails. Those fields and accounts are now kept exactly as they were, and settings sections Minn does not show can no longer be saved from it at all.

  • Update everything installs every language pack again. When a batch updated plugins or themes first, the language packs from wordpress.org were skipped: only packs from commercial plugins installed, and the rest showed as not confirmed. Every pending pack now installs in the same run.

  • Faster updates now follow the site's own download rules. When Update everything downloads several packages at once, each download now goes through the same checks WordPress applies to one download at a time. A plugin that blocks or answers a download itself (an offline or staging guard, for example) is respected, so the package is no longer fetched around it. The site's certificate settings and its curl options apply, logging and monitoring plugins see the downloads, and a plugin that fetches its own update package gets its turn before Minn hands over the copy it already downloaded. The downloads still run side by side.

  • LatePoint bookings could be read or changed by a request from another website while you were signed in. LatePoint keeps its own copy of the signed-in user, and it kept answering for you even after WordPress had rejected a request that arrived without Minn's security token, so a page elsewhere could approve or cancel bookings in your name. Those requests are now refused.

  • ACF fields your site hides from a role stay hidden in Minn. A site can hide an ACF field from some users, or make it read-only, with ACF's acf/prepare_field filter. ACF applies that only on its own screens, so Minn listed those fields, showed their values and saved them for anyone who could edit the post. Minn now asks the same filter: a hidden field is neither shown nor saved, and a read-only one stays in wp-admin, counted under the fields that live there.

  • Saving the ACF panel no longer empties a gallery. When a gallery held an image you are not allowed to attach, saving any other field on the post dropped that image from the gallery. The stored gallery now stays exactly as it was, and images that were deleted from the media library drop out quietly instead of blocking the save.

  • Sucuri's activity log is for the network administrator on multisite. Sucuri keeps one log for every site on a network and shows it only in Network Admin, but Minn showed the whole log to any single site's administrator. It now shows it only where Sucuri does.

  • The database browser hides more sign-in secrets. One-time login links, WordPress salts stored in the database, Wordfence's connection keys and remembered-device keys, and the two-factor seeds and emergency codes kept by Sucuri and All In One Security now show as hidden, and search skips them, like passwords and session tokens already did.

  • AI agents can no longer switch Novamira's safety settings back on through Minn. Novamira changes its on/off switch, its per-ability rules, its connections and its memories only from its own admin screens. Through Minn, the Application Password an agent connects with could do the same. Those changes now need a signed-in browser session, as they do in Novamira.

  • Custom CSS & JS code stays private to people who may edit it. A role that could see the snippet list but not edit a snippet could still read its code, including drafts, from the list or through search. It now sees the snippet's name only.

  • WooCommerce Gift Cards' cart setting shows the right way round, and saving it no longer flips it. Store settings also no longer offers the WooCommerce Subscriptions section, whose own save only accepts its own screen and quietly reset two proration settings when saved from Minn; it stays in wp-admin.

  • Unsaved drafts stay with the person who wrote them. The editor keeps a copy of unsaved work in the browser in case it crashes. That copy is now tied to your account and your site, and signing out clears it, so a shared browser no longer offers one person's draft to the next.

  • Saving a post in Minn can no longer switch on script another author hid in it. Minn's editor keeps risky attributes in stored content switched off while you edit by renaming them, then renames them back when it saves. Content could carry attributes that already looked renamed, and saving the post turned them into working script, so a Contributor could plant code that ran once an administrator opened and saved the post in Minn. Minn now recognizes only the attributes it switched off itself in that editing session; anything else is saved exactly as written and stays inert.

  • Styles inside a post's blocks stay inside the editor. Some blocks carry their own stylesheet in their markup. Minn's previews put it on the page as it was, so it applied to the whole admin: it could repaint or hide Minn's own menus around the preview, and a linked stylesheet loaded the moment someone opened the post. Those styles now apply only inside the editor, linked stylesheets in the markup no longer load, and the post is saved exactly as it was written.

  • Maintenance mode holds back every request from outside the admin. A request that carried a signed-in editor's cookie but no security token (the shape of a request another site could trigger in that editor's browser) still read the site's content while maintenance mode was on. It now gets the maintenance answer, like any visitor.

  • Smaller fixes from the release review. Network plugin switches honor a host's rule that a plugin must stay on. A site administrator on a network can no longer look up themes the network has not allowed for their site. Traffic reports from Matomo link only to pages on your own site. Block previews can no longer replace the fonts or animations Minn itself uses, and Essential Blocks previews no longer load fonts named in a post's markup. A finished update's progress record is removed a few minutes after it ends and no longer includes server paths. Gravity SMTP only accepts a sending service it has registered, and FluentSMTP's Resend to accepts at most 25 addresses, like its own screen. Meta Box fields marked as not saved are no longer editable. Design-library image imports refuse any server that resolves to a private or link-local address. The count of accounts CleanTalk flagged as spam shows only to people who can open CleanTalk's own scan.

  • Post SMTP no longer reports an email its backup mailer delivered as a failure. When the primary connection failed and Post SMTP's fallback mailer sent the message anyway, Minn counted that delivery as failed on the status card, the chart and the Failed filter, and since Post SMTP 4.0.2 records each fallback attempt as its own entry, one rescued email could show up as two failures. Those entries now count as sent, the way Post SMTP's own log screen counts them, and the email's details say the backup mailer delivered it.

  • Bookly staff members linked to more than one staff profile see all of their bookings. Minn looked up only the first Bookly staff profile tied to a WordPress account, so a person who works under two profiles saw fewer appointments in Minn than in Bookly. Minn now scopes the list the way Bookly does, using Bookly's own lookup when it is available.

  • No more dead "Edit in Elementor" button on pages Elementor will not open. Elementor refuses its editor on the posts page and, since Elementor 4.3, on the WooCommerce Shop page, because WordPress shows a listing there instead of the page's own content; Minn still offered the button, which landed on the plain edit screen. The editor now explains why Elementor cannot edit that page, asking Elementor itself, and the front-end toolbar opens the page in Minn instead. Other page builders can report the same through the edit_blocked key on the builder descriptor.

  • Email previews in detail views line up with the rest of the panel instead of sitting indented and running past its right edge.

  • "Database only" backups from the status card back up only the database. On the UpdraftPlus and WPvivid backup cards, the Database only button lost the choice on its way to the server and started a full backup instead; status-card buttons now send everything their action carries, the way list and detail buttons already did.

  • WP Mail Logging shows encoded subjects as text and splits every recipient list. Some plugins send subjects in an encoded form (=?utf-8?B?…?=) that the log kept as-is; Minn now shows them as readable text, as WP Mail Logging's own screen does. Recipient lists stored with a literal \n between addresses no longer show the stray characters.

Don't miss a new minn-admin release

NewReleases is sending notifications on new releases.