Skip to content

Changelog

Every version with everything that changed in it — newest first. What of that you notice day to day is summed up more briefly in New in 2.0.

The list covers both editions. Entries about modules that only the paid edition brings along — statistics, bounce processing, attachments, subscriber variables, SOAP and REST — do not concern the free one; which they are is listed under Lite, Pro and Enterprise.


2.0.0

24.09.2026

New

  • Every backend page now links to its chapter of the manual, next to the heading. Until now only the modules had such a button
  • A Maintenance area under Settings, with a preview of what a cleanup would change
  • Placeholders %nl_onlineurl% and %nl_onlinelink% for the browser view. The previous names keep working
  • The WordPress privacy tools are supported. Tools > Export Personal Data and Tools > Erase Personal Data now cover subscriber records, group assignments, sending records with open timestamps, additional subscriber fields and bounce records. Settings > Privacy offers a suggested text
  • uninstall.php. Deleting the plugin removes nothing unless the setting under Settings > Maintenance says so; with it on, tables, options, the upload folder and the cron entry are removed. The pages created for subscription, confirmation, unsubscribe and archive are always kept
  • The Spam protection module. Protects the subscribe and unsubscribe form without a puzzle, without a third-party service and without storing an IP address — a hidden decoy field, a signed timestamp fetched from your own site, an optional background calculation, content checks and a rate limit. It can replace the captcha module entirely
  • The target group selection of a newsletter shows how many people it reaches. Each group name carries the number of its confirmed subscribers, and the line below the field gives the number for the selection as a whole — anyone in two of the selected groups counts once. It is recalculated as soon as the selection changes
  • The panels on the newsletter screen can be collapsed, the same way panels can be collapsed when editing a post. What you collapse stays collapsed, per user. "Sending test" and "Sending settings" start collapsed — neither is needed while you write the newsletter
  • The same collapsible panels on the screens for subscribers and groups. Each screen remembers its own state
  • A Statistics screen under Newsletter. For every newsletter sent it shows how many people it went to, how many opened it and how many clicked a link, each with a rate; from there the links of a newsletter sorted by clicks, and for each link the subscribers who clicked it. The newsletter list links to it
  • The Openings module is now called Statistics and counts clicks as well. Links in the HTML version then point to your own installation and are forwarded from there to the actual destination; counted per link and subscriber are the first click, the last one and how many. Unsubscribe and confirmation links stay untouched, the text version keeps its plain addresses, and newsletters already sent are not changed. Nothing leaves the installation, no IP address is stored. Off by default: the measurement records the behaviour of individual recipients and normally needs their consent
  • The Statistics screens now draw their numbers as well. The overview compares the opening and click rate of the last twelve newsletters, a newsletter shows recipients, openings and clicks as bars and every link with its share below them, and a link shows the first clicks day by day — that is where you see how long a newsletter keeps working. The numbers stay in the table next to it; the charts add nothing that is not there. They are drawn on your own server, without JavaScript and without loading anything, they print along with the page and they fit a narrow window
  • The list of links now names the text a destination was shown under, in a column of its own next to the address. Two addresses can differ by a single parameter, and the same destination often appears twice under two names — from the address alone you could not tell which link was meant. Where one destination carries several names, they are listed one after another; what is counted is still the destination, not the position. For a link that is an image, its alternative text is used. Newsletters sent before this update stay without it: their list of links is already written, and newsletters already sent are not rendered again
  • The statistics can be taken away as a CSV file — a "CSV export" button next to the heading of each of the three screens. The overview gives one line per newsletter sent with recipients, openings, clicks and both rates; a newsletter gives its links with link text, destination, clicks and share; a link gives the subscribers who clicked it with first click, last click and count. The overview export takes every newsletter sent, not just the page on screen. The rates are numbers in a column of their own, so a spreadsheet can calculate and sort with them. The separator is the one used for the subscriber export (Settings → General)
  • A new installation is ready to work from the first screen. Until now almost every field under "Settings" was empty, and an empty select means "first entry" to the browser — street, post code and city were asked for on the subscription form, and the unsubscribe link was set to "delete subscriber". Now set: the sender from your site name and the administrator address, the WP mailer as the mail engine (it takes the path your site already has, including your SMTP plugin), salutation, first name and name as optional, street, post code and city not asked for at all (a newsletter does not need a postal address), "confirmation mail, subscriber inactive" for unsubscribing via the link, the target group for new newsletters, plus cron system and debug mode. The five pages the plugin needs in the frontend are still yours to create — under "Settings → Pages" with "Create new page"; where the subscription form sits and what the page is called is your call. Existing installations are left alone: every one of these defaults applies to a new installation only, so no field disappears from a running subscription form

Changed

  • The help buttons open the manual in the language of the backend. An English WordPress lands on the English manual, everything else on the German one
  • An access key now applies to the domains registered for it. If this site's address is not among them, the plugin runs as a trial version and shuts down after 14 days. The notice in the backend links to Update access > Domain management, where the address is registered; a Pro key covers one domain, so release the old one first. The 14 days start when the plugin first sees the situation, so an existing installation is never shut down on the day it is updated
  • The mail engine "MIME mailer (up to PHP 5.6)" is gone. It ran through a bundled class from 2005, written for PHP 4, and could do nothing the PHP mailer (PHPMailer from WordPress, with SMTP) and the WP mailer (wp_mail) cannot do better — all three ended up in the same function of the server. If you had it set, your mail now goes out through the WP mailer; the same applies if you never set anything, because an empty setting was exactly that path. A notice in the backend says so and points to the setting. The three fields that existed only for it are gone as well: "Suppress the -f parameter", "Line ending" and "Transfer encoding". The plugin now ships no mail library of its own — and no .inc file, whose source a web server hands out as plain text
  • When a check on the newsletter screen finds something missing, it now says so at the field instead of in a system dialog. The field is marked, its panel opens if it was collapsed, and the cursor jumps there. The questions asked before a step that cannot be undone stay as they are
  • The help page follows the width of your window instead of standing at a fixed 790 pixels
  • For developers only: Everything that talks to the manufacturer's server — updates, access key, domain management and the fourteen-day trial — now lives in its own directory and hooks itself in. The plugin core no longer asks whether it is allowed to run. Own modules that called dienstAktiv(), hasActiveDemoLicence(), hasActiveLicence(), getDemoDays() or read $update_data on the plugin controller need one line changed: call them on wpng_Updatezugang::getSingleton() instead, guarded by class_exists( 'wpng_Updatezugang' ) so the module also runs in the free edition
  • The plugin no longer starts a PHP session. Messages to your visitors are carried across the redirect by a marker in the address; the text sits in the database for five minutes and is deleted when it is shown. That removes the PHPSESSID cookie every visitor used to get once they had seen a message — and with it the reason a page cache would stop serving that page to them. No session file is left on the server either. Own modules that called openSession(), hasSessionCookie(), sessionCookieParams(), clearSessionField() or send_headers() need to drop those calls; if a module redirects on its own, it passes pending messages on with meldungenMitgeben( $target )
  • Every admin page of the plugin now uses the page header WordPress uses itself. The buttons next to the heading — "Create", "Add", "CSV Import" and the rest — were 40 pixels tall next to a 17 pixel heading and stuck out above it; they now sit flush beside it at 32 pixels, like the list screens of WordPress. Own templates under user_views keep their old header and keep working
  • The menu entry "Mailkonfiguration" is now called "Absender und Betreff" (sender and subject). It sat next to "Versandeinstellungen"; both names said the same and meant different things — one is the route (cron, mail engine, SMTP), the other is sender, subject, CC and BCC per kind of mail. The page address is unchanged, bookmarks keep working
  • Three settings now sit where you look for them. "Newsletters in the archive" and "Subscriber for the archive view" were under General and are now under Page configuration, next to the archive page they refer to; "Group after registration" is now under Form configuration, next to the fields of the subscribe form. The values are kept, nothing has to be set again. The entries under Settings now follow the order you set things up in, and the two tools "Save settings" and "Maintenance" sit at the end instead of in the middle
  • The configuration area has been refreshed. It is no longer nailed to 970 pixels but fills the window and wraps on narrow screens — the right half of the help texts used to be cut off in a small window. The tabs look like WordPress tabs, the sub-entries sit in a row below them instead of a column beside them, and the input fields sit in a grid that grows with the window. On the way it turned out that the bar and the boxes pulled their background images from wp-admin/images — WordPress removed those files at the end of 2013. Own templates under user_views are refreshed along with it as long as they use the plugin's form functions; they need no change
  • An empty JavaScript file was loaded on every front end page. It is no longer shipped; if you keep your own copy under wpng_views or user_views, nothing changes for you
  • The folder name of the plugin is no longer written into the code anywhere. Paths and URLs are built with plugin_dir_url() and plugin_basename()
  • Wording throughout. What is sold is "updates and support for twelve months", not a licence and not a subscription
  • The newsletter editing screen follows the width of your window. The two columns used to be nailed to a fixed number of pixels — on a 1024 pixel window the settings took almost as much room as the newsletter itself, and in a narrow window the buttons ran underneath them. Below 960 pixels the settings now move under the content
  • The note under the subject now shows what would actually be sent. Name and subject are two different fields, but the default subject is "%nl_name%" — leaving the field empty sends the name from the top of the screen. The note spells that out instead of pointing at the global settings

Removed

  • The bundled CKEditor. Newsletters are written in the WordPress core editor, which every installation already has. Installations that had CKEditor selected are switched back to the core editor on update
  • lib/composer.phar, a 1.8 MB executable archive that had no task at runtime
  • The plugin no longer downloads and unpacks executable archives at runtime. The mechanism re-fetched add-on modules from a manufacturer server after every plugin update, without a signature check. Modules ship with the package
  • lib/PEAR.php, lib/PEAR5.php, lib/Net/POP3.php and lib/Net/Socket.php, around 2,900 lines of third-party code from 2010 whose upstream project is archived
  • The version number was fetched from a manufacturer server after every update and written to the database, where it could name a version that was not installed. It now comes from the package

Security

  • Confirmation and unsubscribe links carry a much stronger token. Links from mails already sent keep working until you switch the old form off under Maintenance
  • The SOAP interface accepts a new, stronger signature that covers the values of a call, not only the field names. Both forms are accepted; the old one can be switched off
  • The browser view of a newsletter no longer accepts a subscriber number. It used to hand out any subscriber's newsletter including their valid unsubscribe link
  • Attachments are checked against the file types WordPress allows in the media library, by content rather than by file extension
  • The bounce mailbox password is stored encrypted instead of in clear text
  • Creating the text version of a newsletter could run code from the address bar. The conversion stripped the tags first and decoded the entities afterwards, which put the tags back together. The reply is now delivered as plain text
  • A database error no longer prints a backtrace with the values that were passed in — those could include the bounce mailbox password and subscriber addresses. Without debug mode it also no longer ends in an empty page, it names the error
  • The unsubscribe form no longer answers whether an address is on the list. It used to say "no subscriber with this e-mail address was found" for any address, publicly and as often as you like
  • The unsubscribe form now runs the module checks as well. Its fields were always drawn there — it is the same form — but nothing ever looked at them. If you use the captcha module, the captcha is now checked when unsubscribing too
  • The captcha module sent the secret reCAPTCHA key to Google inside the URL, where it ends up in server, proxy and remote logs. It now travels in the request body. An ampersand in the key used to break the request
  • When Google could not be reached, the captcha module let the submission through instead of rejecting it — blocking Google's server for your webserver switched the captcha off without anything looking different in the backend. Every failure now rejects
  • The plugin's menu icon comes from WordPress itself instead of from a manufacturer server. Nothing about your server is transmitted on backend page loads
  • "check mailbox" in the bounce module is now covered by the security check. It fetches the mailbox and, depending on your setting, deactivates or deletes subscribers, so a link slipped to a logged-in administrator could have triggered it

Fixed

  • Registering a domain reported "the registration server could not be reached" although it had worked. The server sends a warning ahead of its answer when a domain is registered for the first time, and the answer behind it was no longer read
  • When the update access runs out, the plugin list now says so and links to the renewal. The notice comes from the update server and was never displayed
  • Settings that sat empty in the database are given their default value. Affected were "Newsletters per page (backend)", "Groups per page", "Subscribers per page", "Newsletters to send per run", "Newsletters in the archive" and "CSV separator for import and export". The field showed nothing while a value from the source code did the work — the newsletter list showed 25 rows although the default says 100. Only filled in where empty cannot mean anything: a count and a separator. Senders, copy recipients and credentials stay empty, there empty is a statement, and a value you set is never touched
  • Right after activation the backend pointed out the missing group — it is checked before the plugin creates it. The notice now goes away as soon as it stops being true
  • When the plugin is updated by hand — files replaced over FTP instead of letting WordPress run the update — the database now picks up its changes by itself. Until now that only happened on activation and on an update through WordPress; until someone clicked "Update now" under Settings → General, new columns were missing. That went unnoticed and could cost data: with click counting on, a mail went out uncounted and nothing in the backend said so. The button stays, it is just no longer the only way
  • The hourly sending run is in the WordPress schedule exactly once again. Every activation and every update added another entry — three of them in our development install, so sending ran three times an hour instead of once. Existing duplicates are cleared with the next update; no run is lost
  • A subscriber name that begins with =, + or @ is no longer executed as a formula when you open the exported CSV file in Excel or LibreOffice. The names come from the subscription form on your site. Such fields now carry a leading apostrophe, numbers are left alone, and the import removes it again — what you export and read back in comes back unchanged. A phone number like +49 170 … now stands in the cell instead of #NAME?
  • On list screens, every checkbox, the bulk action menus and the page number field now carry a name a screen reader can announce. The row checkboxes name the entry they belong to
  • "copy content into the text version" fetched the newsletter list instead of the text version and wrote the whole admin page into the text field
  • A plugin that had never reached the update server wrote a deprecation notice on every admin page under PHP 8.1 and newer, because a stored value of false was turned into an array behind the scenes
  • The "Load beta updates" checkbox under General is gone. It picked which version file was fetched from our server after an update — that request no longer exists in 2.0.0, the version number comes from the package itself. The checkbox switched nothing; a switch that does nothing is misleading. The stored value is left untouched in the database
  • A list with a single hit said "1 Elemente" (plural). It now says "1 Element", in all five overviews — newsletters, subscribers, groups, send log and bounces
  • The "Data collected" screen pointed to the mail configuration for the external SMTP account — it is entered under the dispatch settings
  • The captcha module with "reCAPTCHA v2" let nobody through. The template drew the checkbox but never loaded Google's script, so the field stayed empty — and an empty answer is rejected. With the consent layer switched on, the click loaded a hard-coded release URL that Google now answers with 404. Both paths now load the official script through WordPress's own queue. Check your subscribe form after the update if you use reCAPTCHA
  • A freshly switched on captcha module checked nothing at all, because no check type was stored yet. Switching it on now presets the simple bot trap, which needs no key and no third party. The settings page also points out a missing reCAPTCHA key
  • The simple bot trap answered with a blank page and an English swear word instead of a message. It now shows a notice in the form, and the hidden field is protected against browser autofill
  • A space picked up when pasting a reCAPTCHA key made the check at Google fail without any message. It is now stripped. The captcha module's settings are validated before they are stored, and an incomplete form no longer clears a setting
  • Date placeholders showed UTC instead of the time zone of your site
  • A scheduled newsletter went out at the wrong time if the database server clock disagreed with the time zone of your site
  • The "view in browser" link led to "invalid subscriber" in every newsletter sent
  • A session was started on every page load, including requests by robots
  • Bounce handling ended in a fatal error on every PHP 8 installation. Net_POP3 declared its constructor in the PHP 4 style, which PHP 8 no longer calls, and that was the only place the socket was created. The mailbox is now read through the POP3 class that WordPress itself ships in wp-includes/class-pop3.php
  • Bounce mails were never recognised. The module read the header Message-Id, mail servers write Message-ID. Headers are now read independently of spelling
  • Deleting a subscriber left their sending records and the values of their additional subscriber fields in the database. With the log module switched on, that included the record of when they opened which newsletter
  • Images embedded into a mail were labelled application/octet-stream instead of image/png. Some mail programs offer such an image for download instead of showing it
  • The setting "embed images in mail" did nothing when the mail path "WP Mailer" was selected
  • Images in the supplied layout theme1 were addressed relative to the site root, which no mail program can resolve
  • Inline editing did not save. Renaming a subscriber variable, changing its type or editing a placeholder rule silently reverted to the old value, and attachments could neither be uploaded nor removed. The security check introduced in this version rejected those requests, because the templates did not pass a check value with them
  • A backend page left open for more than a day rejected every inline edit. The check value is now renewed while the page stays open, and if it does expire, a dismissible message says so instead of the change disappearing without a word
  • The plugin's own scripts and stylesheets were delivered with the WordPress version number instead of the plugin version. After a plugin update, browsers kept the old JavaScript and CSS until their cache was cleared by hand
  • The month names in the sending date were always German, whatever language the installation runs in
  • A newsletter that has been sent no longer offers "Add media". Its content is frozen at sending time, and the editor next to the button was already locked
  • The newsletter name field no longer jumps ahead of WordPress's own "Skip to content" and "Skip to toolbar" links when you tab through the page, and it has a name a screen reader can announce

1.1.4

08.09.2023

Fixed

  • An error in access key management and domain registration

Earlier versions

The history before 1.1.4 was only ever kept in German. It follows here as written.

1.1.3

09.08.2023

Neu

  • PHP 8.2 Kompatibilität
  • PHP8 Kompatibilität verbessert
  • Adminbenachrichtigung bei Newsletteranmeldung (optional)
  • DSGVO Layer für reCAPTCHA V2 integriert
  • WPNG user_views können nun im Child Theme abgelegt werden

Behoben

  • Abmeldebutton im Template
  • Versand von HTML-Mail

1.1.2

29.09.2022

Neu

  • Wordpress E-Mail Engine integriert

1.1.1

21.07.2022

Neu

  • Löschen/Deaktivieren von Abonnenten kann optional auch wpShopGermany Kunden deaktivieren
  • Abmeldebutton im E-Mailheader
  • Recaptcha V3 in das Anmeldeformular integriert

Behoben

  • Recaptcha V2 nun nutzbar, Recaptcha V1 wird nicht länger unterstützt
  • Alle Einträge auf einer Seite in der Abonnenten- und Gruppenverwaltung können wieder schnellausgewählt werden

1.1.0

02.11.2020

Neu

  • PHP 7 Kompatibilität / Optimierungen
  • Warnungen reduziert und Code erneuert
  • Widget "An-/Abmeldung"

1.0.5

ohne überliefertes Datum

Neu

  • Erweiterung um Hinweise über Datenspeicherung
  • Abonnenten können mehreren Gruppen zugeordnet werden
  • Versandlog im Backend

Behoben

  • Fehler behoben, bei dem die Archivseite auf bestimmten Seiten falsch angezeigt wurde

1.0.4

17.05.2018

Neu

  • Google reCaptcha für das Registrierungsformular
  • Php7-Kompatibilität realisieren
  • Automatische Verlinkung zur Datenschutzseite aus dem wpShopGermany

1.0.3

03.08.2017

Neu

  • Nutzung der Certifikatsdatei von Wordpress für Kommunikation mit Registrierungsserver
  • Trennzeichen für CSV Im- und Exporte konfigurierbar
  • SOAP Funkttionalität erweitert um Gruppen auszulesen
  • Meldung, wenn Crypt-Bibliothek nicht geladen werden kann
  • Gruppen manuell hinzufügen
  • Abonnenten können auf "inaktiv" gesetzt werden

Behoben

  • Anzeige von Sortierpalte und Richtung in Abonnentenübersicht ausgeblendet
  • Abonnentenvariable wird als Wert, nicht als Index, in Datenbank gespeichert
  • Wenn Gruppen über die SOAP Registrierung definiert sind und ein Kunde den Opt-In bestätigt wird die Standardgruppe nicht mehr gesetzt
  • Meldung wenn Crypt Bibliothek nicht geladen werden kann
  • Aktivierung einer Lizenz kann wieder abgeschickt werden

1.0.3

10.06.2015

Neu

  • Abonnenten lassen sich im Backend sortiert anzeigen
  • Upload Pfad lässt sich in den Allgemeinen Einstellungen einstellen

Behoben

  • Fehler beim abmelden korrigiert (Status auf inaktiv setzen)
  • -f Parameter wird korrekt gesetzt
  • Fehler bei Tabellenerstellung Placeholder korrigiert
  • Ausgaben durch content_filter für aktuelles Wordpress korrigiert
  • CSS Anpasungen für aktuelles Wordpress Theme
  • Platzhalter für UserFields mit Auswahlmöglichkeiten geben gesetzten Wert zurück
  • Kein Fehler beim Speichern der Voreinstellung ohne gesetzte Standardzielgruppe

1.0.2

21.05.2014

Neu

  • Meldung wenn keine Gruppe für Registrierung angegeben ist
  • Übernahme des HTML Textes zu TXT verbessert
  • Abonnent für Archivansicht kann definiert werden damit die Platzhalter ersetzt werden
  • Wird eine Testmail an eine Adresse geschickt die als Abonnent existiert, so werden die Platzhalter ersetzt
  • Modul "Platzhalterregel" für individuelle Platzhalter z.B. für Anreden
  • Wordpress 3.9 Kompatibel

Behoben

  • Seiten werden korrekt mit URL Pfad angelegt
  • Fehler bei PRIMARY KEY Definition für dbDelta behoben
  • Standardlayout wird korrekt gespeichert, damit es für neue Newsletter verwendet wird

1.0.1

10.04.2013

Neu

  • Installation in Unterordner möglich
  • -f Parameter kann bei internem Mail deaktiviert werden

Behoben

  • Übersetzungen korrigiert
  • Fehler beim aktivieren (Unerwartete Ausgaben) behoben
  • CSS/JS werden aus userviews verwendet wenn vorhanden
  • MimeType Erkennung mittels fileinfo bei Intern(mail)

1.0.0

ohne überliefertes Datum

Weitere

  • Erste Version