30% off Pro plugins with LAUNCH30 See plugins
v1.0.8
12 September 2026

Your licence now keeps working after it lapses. Pro features stay on for every activated site; renewing restores updates and support on the same key.

  • The licence screen shows Lapsed, and what that means, instead of a red Expired.
  • Enforcement, trusted devices and risk checks already kept running after expiry; reports, settings and customer 2FA now do too.
  • New versions are fetched only while the licence is current. Nothing else changes.
v1.0.7
12 September 2026

Schema stamping, settings saves and webhook-secret rotation now report failures instead of success.

What's fixed in 1.0.7

  • The metadata table is verified before its schema version is stamped. If the table could not be created, the version was recorded anyway and the creation was never retried. The stamp now waits for the table to exist. If the table cannot be created (typically a database user without the CREATE privilege), administrators see a notice naming it; creation is retried every 10 minutes rather than on every request.
  • Settings saves are verified. The Pro settings screen showed "Settings saved" regardless of whether the write succeeded. A failed save now shows an error and tells you the previous settings are still in effect.
  • Webhook secret rotation cannot show a secret the site is not using. If the new secret could not be stored, the screen still displayed it for you to pin on the receiving end. Rotation now reports the failure and the previous secret stays in use. The same applies when a secret is minted on first configuring a webhook.
  • "Remember this device" only sets its cookie once the record is stored. A cookie naming an unknown token is no longer issued.
  • Sites already missing the table are repaired on upgrade. An earlier version could record the schema as up to date even when the table had not been created, and because that recorded version did not change in this release those sites would have skipped the new check forever. The table is now confirmed to exist before the recorded version is trusted, so an affected site repairs itself the next time an administrator opens a WordPress admin page.

No settings, data or behaviour changes otherwise.

v1.0.6
23 August 2026

Security fix: device-risk detection now works correctly behind a proxy/CDN; secrets are authenticated at rest.

= 1.0.6 =

  • Security: the risk engine now uses the same proxy-aware client IP as brute-force protection, restoring new-device detection behind a load balancer/CDN.
  • Hardening: authenticated encryption at rest; a stored licence is re-checked for a usable key before trusting the cached result.
v1.0.5
22 August 2026

Tested and verified on WordPress 7.1.

  • Compatibility: tested up to WordPress 7.1.
v1.0.4
19 August 2026

Important: two-factor enforcement, trusted devices and risk checks now keep protecting your site if your licence lapses — an expired card no longer silently switches off protection. Reports and settings changes still need an active licence.

v1.0.3
17 August 2026

Your data now survives uninstall by default.

Uninstalling no longer deletes the plugin's data unless you explicitly opt in first, so removing it to debug — or coming back later — keeps everything intact. Where the plugin has a settings screen you'll find a new "Delete all data on uninstall" option; leave it off to keep your data.

v1.0.2
16 August 2026

A cleaner, consistent look: the Dragon design system arrives.

This release brings Dragon Core's design system to every screen: a consistent header with the Dragon mark, cleaner tables, and unified status colours across the whole plugin family. Purely visual — everything behaves exactly as before.

v1.0.1
10 August 2026

No notes for this release.

v1.0.0
4 August 2026

No notes for this release.