New in 2.0¶
The biggest overhaul since version 1. This page names what changes for you — the complete list is in the changelog.
Your update access may be due for renewal
Up to 1.1 the plugin did not check the access key reliably, and it did not always point out when updates and support were due for renewal. Since 2.0 it does both.
A renewal may therefore be due after the update that you saw no sign of before. What applies to your installation is shown under Update access.
At least read What can change
Three things can be different after the update, and the plugin reports all of them in the backend. Plus one change from 2.0.1 to the subscription form.
New modules¶
Spam protection¶
Five layers against automated sign-ups, invisible to the visitor. No picture puzzle, no call to the outside, no stored IP address. Switch it on and you can switch the captcha module with Google reCAPTCHA off.
Post notification¶
A published post becomes a newsletter — immediately or collected as a daily or weekly digest. With a window of 15 minutes in which everything can still be changed.
REST interface¶
Third-party systems over HTTP, without the PHP extension soap. Its own key,
its own switch. SOAP runs alongside it unchanged.
„Log" became two modules¶
| Module | Package | |
|---|---|---|
| Who received the newsletter | Sending log | both |
| Who opened and clicked it | Statistics | Pro |
If „Log" was active, both are active after the update, and your setting for the tracking pixel stays. Opens already counted are kept.
The subscription form now goes everywhere¶
Until now it went on exactly one page — and through a widget that does not even exist any more in the themes WordPress has shipped since 5.9.
Since 2.0 there are four ways: subscription page, shortcode, block and „under every post".
On top of that:
- a short version — address and button only, for the space under a blog post;
- a group per form through
groups="…", so that the form under the blog leads into a different group from the one on the offers page; - returning to the same page after submitting. Somebody subscribing under a post no longer loses the post.
The form also works with the browser: the address field is an address field (on a phone the keyboard with @ appears), the address book can autofill, and a required field is one for the browser too.
And it looks like your website instead of like a form from 2012: typeface, colours and the button now come from the theme.
Ten new templates¶
Schlicht, Kopfbalken, Rahmen, Zeitung, Karte, Breit, Dunkel, Kompakt, Zweispaltig and Brief. Built for mail programs, including Outlook, and legible on a phone.
On top of that:
- Newsletter → Templates, a gallery with all layouts side by side — each with your logo, your colour and your site name;
- an accent colour under Defaults. The text on it turns black or white by itself;
- logo settings: site logo, custom image or none, plus alignment and width;
- names instead of file names in the selection — „Schlicht" instead of
schlicht.phtml.
Your existing layouts remain unchanged and can still be selected.
If you copied „Beispiel" (theme1): please check
The template contained a sample imprint with a telephone number and links to other people's domains — anyone who adopted it and overlooked that passage was sending somebody else's contact details. And it showed our logo, which thereby appeared in every mail without you having agreed to it.
Both are fixed in the supplied version. Not in your copy under
user_views — no update touches that.
The consent record¶
What is recorded is no longer only when somebody consented but to what — with the complete wording and the page the form was on. Visible on the subscriber and in the disclosure under Art. 15 GDPR.
No IP address, no browser: the click in the confirmation mail is the stronger evidence.
Subscribers from before 2.0 keep their two timestamps; no wording is slipped in for them afterwards.
See Consent.
Statistics with clicks and charts¶
The „Opens" module is now called Statistics and optionally counts clicks as well — per link and subscriber, with first click, last click and count.
New is the page Newsletter → Statistics with three views, charts and CSV export. It is drawn on your server, without JavaScript and without anything being loaded from elsewhere.
Off out of the box, like open tracking: both record the behaviour of individual recipients.
Two new pages in the backend¶
Data collected¶
What is stored on your installation — in the core and in every module running there, including the table, the retention period and what leaves the installation. Meant as the basis for your privacy policy.
Maintenance¶
The jobs you rarely need and then need immediately: cleaning up legacy data, renewing keys, deciding what happens on uninstall.
The backend looks like WordPress¶
The configuration area is no longer nailed to 970 pixels but fills the window and wraps on narrow screens. The tabs look like WordPress tabs.
In the process it turned out that the bar and the boxes were fetching their
background images from wp-admin/images — files WordPress removed at the end
of 2013.
Also:
- The boxes in the newsletter, subscriber and group forms can be collapsed and expanded, and the state is remembered per user.
- The newsletter form adapts to your window; below 960 pixels the settings sit below the content instead of next to it.
- The target group selection shows who the newsletter reaches — per group the number of confirmed subscribers, and below it the total of the selection, duplicates counted once.
- Error messages appear at the field concerned instead of in a system dialogue.
Three settings are now where you look for them¶
| Setting | Was | Is now |
|---|---|---|
| Newsletters in the archive | General | Page configuration |
| Subscriber for the archive view | General | Page configuration |
| Group assignment after subscribing | General | Form configuration |
And „Mail configuration" is now called Sender and subject. The addresses stay the same, bookmarks do not break.
A new installation is ready to work straight away¶
Until now almost every field under Settings was empty — and to a browser an empty select means „first entry". For the mail route that was the MIME mailer, the subscription form asked for street, post code and city, and the unsubscribe link was set to „delete subscriber".
Now sensible defaults are set: sender from the name of your website, WP mailer as the mail route, salutation/first name/last name optional, postal address not at all, „confirmation mail, subscriber inactive" when unsubscribing.
Existing installations are left untouched. Each of these defaults applies only to a new installation.
What can change with the update¶
Three things from 2.0 — the plugin reports all three in the backend, and all three can be dealt with in one click. Plus a change from 2.0.1 that asks nothing of you.
Your address has to be on the key¶
This affects every paid installation that never registered a domain. Up to 1.1 the registration was an optional step: anyone who entered the key carried on working. The key server does not check the address, after all — the same key answered the same way for every domain. So the rule „Pro is valid for one domain" existed only on paper.
Since 2.0 the plugin asks for both: a valid key and a registered address. Without the registration it runs like a trial version and shuts itself down after fourteen days.
You lose no time by this. The deadline begins on the day the plugin first sees the situation — not on the day you bought. A message in the backend says so from the first hour and links to the way out: Configuration → Update access → Domain management → Register this domain. One click.
Everything about it is under Update access.
Who may open the newsletter administration¶
The default is now administrators. Until now it hung on edit_posts, that
is, on authors too.
Why: with that, an author sees the complete subscriber list — all addresses, all names, all postal addresses. And they can write HTML into a newsletter that is executed in the preview and in the archive.
If editors worked on the newsletter in your installation, set it back under General. A setting already in place is not touched.
Plus in 2.0.1: a known address is no longer turned away¶
This affects every installation, the free one included. Up to 2.0.1 the subscription form turned away every address already on the list with "A subscription for this e-mail address already exists" — including the address of someone who had unsubscribed and wanted back. Now it depends on the state, and subscribing again works.
What you will notice: people who unsubscribed can come back without you doing anything, and the message after submitting no longer reveals who is on your list. Nobody who unsubscribed becomes active silently in the process — they always get the confirmation mail first.
The rules in detail are under Placing the subscription form.
The mail route¶
The MIME mailer is gone. It ran over a bundled class from 2005, written for PHP 4, and could do nothing the other two cannot do better.
Anyone who had it configured sends over the WP mailer from the update on — the same applies if nothing was ever configured, because an empty setting was exactly that route. The sender stays the same.
What can change: if you use an SMTP plugin, you now send over its connection. As a rule better, occasionally different.
Security¶
More than twenty items. The ones you should know about:
| The browser view handed out other people's newsletters | With a subscriber number appended, anyone could count upwards and look at other people's newsletters — complete with a valid unsubscribe link. Anyone counting through the list could unsubscribe your subscribers |
| The unsubscribe form revealed who is on your list | It answered differently for an unknown address than for one on the list. Publicly, without logging in, as often as you like |
| „Settings backup" put every secret into the file | In clear text. Whoever got the file could build valid unsubscribe links for every subscriber. Now only with a password and encrypted |
| The links in mails get a stronger signature | The previous one could be reproduced with enough computing time |
| A recorded SOAP call was valid indefinitely | Now 15 minutes, and the new signature covers the values too |
| The captcha module let people through on an error | If Google was unreachable, the captcha was effectively off without looking any different |
| No more PHP session | The PHPSESSID cookie for every visitor who ever saw a message is gone — and with it the reason why a page cache stopped serving that page |
Plus: nonces on all backend actions, prepared database statements throughout, checking attachments by their content instead of their extension, templates only from the three intended directories.
Dropped¶
| Why | |
|---|---|
| CKEditor | A 2012 version with no security updates. Anyone who had chosen it gets the WordPress editor |
| MIME mailer | See above |
composer.phar (1.8 MB) |
Sat in the package with no purpose |
| phpseclib (1.3 MB) | Belonged to reading a licence file — that route has not existed since 2020 |
| The „load beta updates" checkbox | It no longer switched anything |
Wording¶
„Subscription status" is now called Edition, „licence management" is now Update access, and without a key it says „without update access" instead of „demo version" — the plugin is complete without a key too.
Also new: the expiry of your access now appears in the plugin row. Our update server has always sent that message along; up to 1.1 the plugin displayed it nowhere, and the expiry only became apparent when an update failed to arrive.
What is sold is neither a right to use GPL code nor a subscription, but updates and support for twelve months.
