Changelogs

Follow the improvements and fixes in each product release.

Products

Recent Releases

Permalink

Osmium 0.4.0

Four sample sites now ship inside the theme. Their six pages are patterns in a new group, Full Pages. You can start an author site, a book review blog, a bookshop, or a literary magazine from the inserter instead of from a blank page.

Install

Download osmium-0.4.0.zip below, then go to Appearance → Themes → Add New → Upload Theme. Upgrading from 0.3.x is a straight replace: upload the zip and confirm the replace when WordPress asks.

New in this release

Full Pages, a new pattern group. It has six complete pages, the same ones that run the sample sites on the demo:

  • Author site: home. The new book, praise, the backlist, an about section, events, and a newsletter signup.
  • Author site: book page. The details in a table, the opening page, praise, and notes for reading groups.
  • Book review blog: home. Your latest reviews, a best-of list, genres to browse, and how the ratings work.
  • Bookshop: home. Staff picks, a book club on three plans, events, and opening hours.
  • Bookshop: staff picks. Recommendations grouped by bookseller.
  • Literary magazine: home. The current issue, past issues, a submissions call, the masthead, and subscriptions.

They’re offered when you create a new page. Your site’s header and footer wrap them, the post lists pull in your own posts, and every word is translatable.

Covers that ship with the theme. Ten book covers, three magazine covers, and two bookshop shelf images, 210 KB in all as WebP. The books, people, and publishers on them are made up, ready for you to swap in your own.

The Theme URI points to the theme’s page. It now goes to https://gauravtiwari.org/product/osmium/ instead of the GitHub repository.

The theme now ships

| | | |—|—| | Templates | 22 | | Template parts | 11 | | Patterns | 128, in eleven groups | | Designs | 6, plus 5 palettes and 4 type presets | | Pattern images | 27, all generated for Osmium | | Theme JavaScript | none |

Checked, not assumed

All 637 blocks in the new patterns validate in the WordPress 7.1 block editor, and PHPCS is clean. axe-core reports zero WCAG 2.2 AA violations on each new pattern at desktop and mobile, and every image loads. The zip was installed over 0.3.0 on a clean site, and every pattern registered.

Known limits

  • The post lists on the review blog and magazine pages show your latest posts from every category. To narrow one, set a category in its Query Loop settings.
  • Links in the new pages point to #, and the email links use made-up .example addresses. Change both after you insert a page.
  • Each full page opens with its own main heading. Use the “Page, no title” template for these pages, so the page title isn’t printed twice.
Permalink

Osmium 0.3.1

Headers, footers, and breadcrumbs now line up with the rest of the page.

In 0.3.0 their rows sat at the reading width, 42rem, while wide sections, featured images, and the front page ran at 72rem. On a large screen the logo and menu sat well inside the edges of everything below them. Now they span the wide width too.

Install

Download osmium-0.3.1.zip below, then Appearance → Themes → Add New → Upload Theme. Upgrading from 0.3.0 is a straight replace: upload the zip and confirm the replace when WordPress asks.

Changed

  • All nine headers and all nine footers span the wide width, so logos, menus, and footer columns line up with the edges of wide content.
  • Footer text keeps its readable line length. A heading, a short paragraph, and buttons in a footer band start at the wide edge but don’t stretch across it.
  • Breadcrumbs at the foot of posts, pages, and archives span the wide width, so they line up with the footer beneath them.

Checked

Every changed pattern and template validates in the WordPress 7.1 block editor, and PHPCS is clean. axe-core reports zero WCAG 2.2 AA violations on the front page, the four post templates, a page, a category archive, and search results, at desktop and mobile. At a 1280px window, the header, footer, and breadcrumbs now run from 64px to 1216px, the same edges as wide content.

Known limits

  • If you edited your header or footer in the Site Editor, your saved copy wins and keeps the old width. Reset the template part to get the new one, or set its rows to wide width yourself.
  • A header or footer pattern you inserted by hand keeps the width it had when you inserted it.
Permalink

Osmium 0.3.0

The library is now big enough to build a whole publication from: 122 patterns and 22 templates, up from 37 and 11, plus two more dark designs, five palettes, and four type presets.

Install

Download osmium-0.3.0.zip below, then Appearance → Themes → Add New → Upload Theme. Requires WordPress 7.0 and PHP 7.4. Upgrading from 0.2.0 is a straight replace. Templates you customised in the Site Editor keep your version.

New in this release

Templates, now 22. Category, tag, date, privacy policy, and attachment templates join the hierarchy. Six more can be picked per post or page: a cover header, a split header, a sidebar, a wide page, a landing page with a minimal header and footer, and a blank canvas.

Posts end properly. An author box and related posts sit under every article. Breadcrumbs sit at the foot of posts, pages, and archives rather than above the title.

Four new pattern groups. Post lists: grids, lists, a magazine front, cover cards, and a timeline. An Article kit: key takeaways, contents, notes, warnings, numbered steps, definitions, code samples, and before-and-after images. Sidebar blocks. And Post layouts, which give a new post a starting structure for a review, a roundup, a how-to guide, a comparison, an interview, a news post, or an essay.

A bigger review kit. Eighteen patterns: scores, an at-a-glance box, roundup picks, top picks, alternatives, plan comparisons, a buyer’s checklist, a disclosure note, a final verdict band, and tabbed details on the core Tabs block.

More openers, sections, and pages. Thirteen openers, twenty-eight sections including pricing, services, team, timeline, gallery, and events, and twelve full pages including contact, work with me, portfolio, advertise, link in bio, coming soon, and an affiliate disclosure. Every pattern image ships with the theme.

Designs. Graphite and Espresso join Midnight as dark designs that keep dark sections dark. Five palettes (Ink, Moss, Plum, Harbor, Rose) and four type presets use the same two fonts and the same spacing, so switching never breaks a layout.

Headings open every section. Small labels above headings are gone throughout, and a post’s category now sits in the meta line under its title.

Fixed

  • Category lists built on the Terms Query block pass their settings the way WordPress 7.1 reads them.
  • The feed link follows the site address, so it works on a subdirectory install.
  • Striped tables follow the palette instead of a fixed light grey, so they stay readable in the dark designs.
  • Header, footer, and sidebar text is translatable.

The theme now ships

| | | |—|—| | Templates | 22 | | Template parts | 11 | | Patterns | 122, in ten groups | | Designs | 6, plus 5 palettes and 4 type presets | | Section and block styles | 6 of each | | Theme CSS | 8.2 KB | | Theme JavaScript | none |

Checked, not assumed

Every pattern, template, and part validates in the WordPress 7.1 block editor. PHPCS is clean, and Theme Check raises nothing beyond an informational note. Color contrast passes in all eleven palettes, measured by script. axe-core reports zero WCAG 2.2 AA violations on every template, at desktop and mobile, in the default design and in Graphite.

Known limits

  • Patterns are copied into a post when you insert them, so anything you built from 0.2.0 patterns keeps its old layout until you insert the pattern again.
  • First-paint CSS on a post is about 84 KB, most of it core’s Navigation block and global styles. It gets a closer look before 1.0.
  • Built and tested on WordPress 7.1. The 7.2 beta opens on 20 October and this will be retested then.
  • The Front Page template takes precedence over a static front page you set yourself. To use your own page, edit or delete that template in Appearance → Editor → Templates.
  • Not submitted to the WordPress.org theme directory yet.
Permalink

Osmium 0.2.0

Fifteen more patterns, and somewhere to find them. The library had two visible groups while the headers and footers sat under core’s categories where nobody looks. There are now six Osmium groups in the inserter.

Install

Download osmium-0.2.0.zip below, then Appearance → Themes → Add New → Upload Theme. Requires WordPress 7.0 and PHP 7.4. Upgrading from 0.1.0 is a straight replace; nothing you have built changes.

New in this release

Headers, now five. Alongside centered and minimal: one with a call to action for a site that sells, one with a notice strip for an announcement, and one with search in the open for a site with a deep archive.

Footers, now five. A signup band, a centered stack for a personal site, and a dark closing band that follows whichever palette is active rather than turning white.

Openers, a new group of five. The newsletter band moves here, joined by a text and image split, a centered statement with one clear next step, a single sentence for an essayist, and one that leads with whatever you published last so the top of the page changes on its own.

Five more sections. A numbers row, a three-step explainer, a section with the heading beside the text so a long passage keeps its measure, a callout note for inside an article, and a keep-reading block for the end of one.

Every pattern that pulls posts carries an empty state, so a new site never renders a heading with nothing under it.

The theme now ships

| | | |—|—| | Templates | 11 | | Patterns | 42, in six groups | | Style variations | 4, plus 3 section styles | | Theme CSS | 8.0 KB | | Theme JavaScript | none |

Checked, not assumed

Every pattern and template validates in the block editor. PHPCS is clean. Colour contrast passes in all four palettes, measured by script. axe-core reports zero WCAG 2.2 AA violations across every template and every new pattern, at desktop and mobile, on a fresh install and a populated one.

Known limits

  • Tested on WordPress 7.0 and 7.1. The 7.2 beta opens on 20 October and this will be retested then.
  • The Front Page template takes precedence over a static front page you set yourself. To use your own page, edit or delete that template in Appearance → Editor → Templates.
  • Not submitted to the WordPress.org theme directory yet.
Permalink

Osmium 0.1.0

First public release. Early, but complete enough to run a real site, and everything in it has been checked rather than assumed.

Install

Download osmium-0.1.0.zip below, then in your WordPress admin go to Appearance → Themes → Add New → Upload Theme. Requires WordPress 7.0 and PHP 7.4.

On activation you get a designed front page straight away, filled with your own posts. Nothing is created in your database and no settings are changed.

What is in it

  • 11 templates: front page, blog home, index, single, single with sidebar, page, page without a title, archive, author, search, and 404
  • 27 patterns, including a review kit of seven: verdict, pros and cons, spec table, comparison table, best-for cards, product call to action, and a deal strip
  • Four page-creation patterns: homepage, about, newsletter landing, and tools
  • Four style variations: Editorial by default, plus Paper, Signal, and Midnight for dark
  • Three section styles for tinted, dark, and card sections, so patterns stay core blocks
  • Two bundled fonts, Valley Sans and Hedvig Letters Serif, self-hosted and served from your own domain under the SIL Open Font License

No JavaScript ships with the theme. No post types, no blocks, no shortcodes, no settings page. Everything you build keeps working if you switch themes.

Checked, not assumed

| | | |—|—| | Theme Check | 0 required, warning, or recommended issues | | PHPCS, WordPress standards | clean across 27 files | | axe-core, WCAG 2.2 AA | 0 violations on every template, desktop and mobile, on a fresh install and a populated one | | Colour contrast | every pair in all four palettes measured by script | | Theme CSS | 8.0 KB |

Known limits

  • Tested on WordPress 7.0 and 7.1. WordPress 7.2 beta opens on 20 October and this will be retested then.
  • The Front Page template takes precedence over a static front page you set yourself. To use your own page, edit or delete that template in Appearance → Editor → Templates.
  • Not submitted to the WordPress.org theme directory yet.

Feedback and bug reports are welcome in the issues.

Permalink

GT Performance 1.0.10

Added

  • Unused CSS status on the Optimization tab: queued, processing, ready, stale, failed, and skipped results; original and generated sizes; reduction percentage; build duration; and failure details.
  • Manual status refresh, per-URL and per-result force regeneration, and full regeneration in bounded background batches. Known eligible URLs and the homepage are queued; other pages rebuild when visited.
  • Counts across all stored reports, with the latest 50 results shown in the table. Current savings exclude stale results and missing generated files.

Fixed

  • Signed CSS generator requests were blocked by page-cache and commerce query rules. The authenticated build parameter is now excluded from the policy context while other request protections remain intact. Build responses remain private and are never cached.
  • Generator tokens no longer become part of report URLs or CSS reuse keys.
  • HTTP errors and responses without completed CSS reports now fail the background job so its retry policy applies. Successful generation purges the public page cache so visitors receive the new CSS.
  • CSS reuse now accounts for the URL, full markup, and CSS revisions, preventing mismatches involving IDs, attribute values, and DOM relationships. Forced builds bypass existing results.
  • Regeneration controls check saved rollout, exclusions, safe mode, and optimization ownership, and avoid duplicating active jobs. Disabled or newly excluded jobs record a skipped result.
  • Consistent padding and spacing across status cards, statistics, reports, and regeneration controls.
  • Clearer help text across optimization and cache settings.
  • WordPress.org builds omit the self-hosted Update URI header. FluentCart URL handling uses WordPress parsing helpers, and the early Redis drop-in documents its filesystem fallback.
Permalink

GT ACF Blocks Plugin 2.11.3

What’s Changed

Fixed

  • Block stylesheets were never cache-busted by a plugin release. Core’s register_block_style_handle() reads $metadata['version'] from block.json and falls back to false, which makes wp_register_style() stamp the WordPress version onto the URL. Every one of this plugin’s block.json-registered handles was therefore versioned by core, not by the plugin: on this site url-preview.min.css shipped as ?ver=7.1 for WordPress 7.1, and the files are served public, max-age=31536000. The query string is the only thing that can retire a year-long cached copy, so a CSS fix in a plugin release stayed invisible to every reader who had already loaded the page until WordPress itself updated. The 2.11.2 contrast fix was landing this way — correct on disk and at the CDN, still broken in the browser of anyone who had visited before.

A block_type_metadata filter now sets version to ACF_BLOCKS_VERSION for blocks whose block.json lives inside this plugin, matching what the plugin’s direct wp_enqueue_style() calls have always passed. Blocks that other plugins register under the acf/ namespace are left alone. Asset URLs now carry the plugin version and change with every release.

Sites running GT Performance saw this compounded: its assetVersion filter rewrites ver when it equals the core version, turning ?ver=7.1 into a stable hash. It was doing its job — hiding the core version — but the versioning underneath was already wrong, and the hash made the staleness harder to spot.

Commits

  • 2.11.3: version block.json assets with the plugin, not with WP core (a91797b)
  • 2.11.2: fix white-on-white URL Preview button in dark mode (e40be8e)

Stats

  • Commits: 2
  • Changes: 11 files changed, 82 insertions(+), 10 deletions(-)

Plugin Info

  • Blocks included: 29
  • Requires WordPress: 6.0+
  • Requires PHP: 7.4+
  • Requires: ACF Pro 6.0+ or Secure Custom Fields

Installation

  1. Download acf-blocks-plugin-*.zip from the assets below
  2. Go to Plugins → Add New → Upload Plugin in WordPress admin
  3. Upload the zip file and activate
Permalink

Functionalities 1.6.1

What’s Changed

  • Fixed: The WordPress 7 data panel no longer appears for a module that is switched off. On a site with Redirect Manager disabled, its page still rendered two empty tables and a working “Add redirect” form, even though the module refuses every write while disabled, so the form could only produce an error.
  • Changed: The panel’s “WordPress 7 workspace” heading is gone. Its tables already carry their own headings, and naming a section after the WordPress version labelled the implementation rather than what you are looking at.
  • Fixed: The Performance & Cleanup settings page was headed “Miscellaneous (Bloat Control)”, which matched neither the module card you clicked nor any other name in the interface.
  • Changed: The dashboard box holding the AI opt-in is now called “AI explanations”, after the single setting it contains, instead of advertising four platform features that are not configurable there.
  • Fixed: Link Management’s JSON preset filter note now matches the format used by every other filter note in the plugin.

= 1.6.0 = = 1.6.1 = Interface fixes. The WordPress 7 data panel no longer appears for modules you have switched off, where it offered a create form that could not work. Several admin headings now match the module names they belong to. No settings, data, or hooks change.

Commits

  • Ship 1.6.1 (933f1be)
  • Stop the WordPress 7 panel labelling itself, and hide it when the module is off (b063842)

Full Changelog: https://github.com/wpgaurav/functionalities/compare/v1.6.0…v1.6.1

Permalink

Functionalities 1.6.0

What’s Changed

  • Security: Abilities API operations now use a permission callback per ability and reject undeclared input properties. A shared callback previously widened to edit_post whenever the request carried a post_id, so any user who could edit one post could toggle modules, create redirects, create tasks, and trigger scans.
  • Security: Redirects, the bounded 404 log, and Task Manager projects moved to a private folder with a random name under wp-content/functionalities/. Existing files are migrated automatically. Apache, IIS, and directory-listing rules are written alongside them, and a new Site Health check confirms over HTTP that the folder really is unreachable.
  • Fixed: Header and footer snippets are no longer re-filtered against the visitor’s capability at output time. Anonymous visitors were receiving mangled code — && became && and comparison operators were eaten as tags — while the logged-in administrator saw the snippet work. Filtering now happens once, at save time, against the author’s capability.
  • Fixed: A JSON exception preset served from a URL is fetched at most once per cache window instead of on every page load. The cache clears whenever the module settings change, a post or page is edited, or the theme changes, and the last good list is kept when a fetch fails.
  • Fixed: The bulk nofollow tool pages through posts with an ID cursor and now finishes on sites with more than 100 matches. It previously returned the same first batch on every run.
  • Improved: Link Management, Block Cleanup, and Schema use the WordPress HTML API instead of DOMDocument. Attributes are edited in place, so Vue, Alpine, and mustache syntax survive untouched and the JS-framework skip guard added in 1.4.3 and 1.4.4 is gone. Content that used to be skipped is now processed correctly.
  • Improved: Redirect hits and 404 aggregates are buffered and written in batches rather than rewriting the whole JSON file under an exclusive lock on every request.
  • Improved: Redirects run at parse_request, before WordPress queries the database for a page it is about to discard. WordPress’s own entry points are never redirected.
  • Improved: The Content Integrity column on the posts list reads a result cached at save time instead of rendering and parsing every row on every page load.
  • Improved: The SVG icon library is stored without autoloading, so full SVG markup no longer loads on every request.
  • Improved: The service worker skips wp-admin, the login page, REST responses, cross-origin requests, and anything marked no-store or private; caps the runtime cache; and precaches URLs individually so one stale entry cannot stop it installing. The manifest now includes an id.
  • Improved: Login Security adds per-username throttling, an IP allowlist, an unlock button on the lockout log, and a warning when every recent lockout shares one address, which is the signature of a site behind a CDN.
  • Improved: Prism.js is bundled with the plugin instead of being loaded from a third-party CDN.
  • Improved: Performance & Cleanup makes the revision limit configurable, and disabling Heartbeat now applies to the frontend only unless the new admin option is also enabled, so autosave and post locking keep working.
  • Improved: Content Integrity and Assumption Detection gained the filters their documentation promised, and the module documentation now lists hook names that exist. Nineteen documented hooks were never fired.
  • Fixed: Settings export no longer redacts the GA4 measurement ID as if it were custom code.
  • Fixed: Core icons get the same definition-ID prefixing as custom icons, so two gradient icons on one page no longer collide.
  • Fixed: Saving PWA settings flushes rewrite rules once instead of twice.
  • Fixed: Disabling feeds falls back to a message only when a redirect is genuinely impossible, making the documented message filter reachable.
  • Changed: The translation template is generated from the source. It was a one-string placeholder.
  • Changed: src/ and docs/ are excluded from the distribution, and build.sh now uses the same exclude list as the release workflow so a local build and a tagged release cannot drift.
  • Changed: Tested up to WordPress 7.1.

= 1.5.0 = = 1.6.0 = Security release. Fixes an Abilities API permission flaw that let any user who could edit a post reach administrator-only operations, moves redirect and task data into a private folder, and stops header/footer snippets being mangled for logged-out visitors. Also replaces DOMDocument with the WordPress HTML API in three content filters, so pages using Vue or Alpine are processed correctly instead of skipped. Existing settings, hooks, admin URLs, and data files are migrated automatically.

Commits

  • Readme: test against WordPress 7.1, correct stale claims, link the docs site (bbcd38d)
  • Fix CI: ship the Prism assets and make the POT check reproducible (c199bbd)
  • Migrate legacy data even when the file modules are disabled (e1c467d)
  • Ship 1.6.0: Abilities permission fix, private data storage, HTML API filters (c5cdccd)

Full Changelog: https://github.com/wpgaurav/functionalities/compare/v1.5.0…v1.6.0

Permalink

GT Page Blocks Builder 3.0.0

A correctness release. It repairs paths that silently corrupted or discarded work, gives the plugin a test suite and CI for the first time, and makes the upgrade itself verifiable.

Back up your database before upgrading — the schema change is one-way. Requires PHP 8.1. Flush your page cache and CDN afterwards: generated CSS and JS filenames now carry a content hash.

Breaking

  • PHP 8.1 is the minimum. WordPress will not offer this to a site below it, and activation stops with a notice instead of a white screen.
  • The CSS minifier no longer collapses whitespace around :. .menu :hover stays a descendant selector instead of silently becoming .menu:hover. If a stylesheet unknowingly depended on the collapsed form, that rule changes what it matches — this fixed eight blocks on our own site whose typography had quietly stopped applying.
  • Minified JavaScript changes shape. A line comment no longer swallows the rest of the file, and newlines survive so semicolon-free code is not concatenated. Blocks whose JS silently did nothing start working.
  • Generated asset filenames carry a content hash. Every cache and CDN misses once. The old unhashed name is still written as a copy for this major version.
  • Utility-class output is switched off once during the upgrade, with a notice. The scanner never emitted anything for page blocks, so this is a zero-visual-change upgrade; turning it back on is your decision.
  • PHP execution in the block preview requires administrator access. It previously ran for anyone who could edit the post.
  • The AI panel requires manage_options. Restore with add_filter( 'gt_pb_ai_capability', fn() => 'edit_posts' );.
  • The undocumented terminal endpoint is removed.
  • Uninstalling deletes options, transients and stored AI keys. The library is dropped only if you tick the new setting.
  • Library usage counts change on block themes, where the invalidation hooks were never registered.

Correctness

Editing a library block reaches the visitor — in file-output mode the generated file was written once and never again. The builder stops blanking core and third-party blocks on every keystroke. Renaming a section persists. A failed save says so instead of showing a green notice over a discarded session. Inline SVG backgrounds survive the CSS sanitiser. A block detached from the library stops rendering the library version over your own copy.

Recovery

Library blocks keep a revision history with one-click restore. Document-level undo covers add, delete, duplicate, reorder and import. Cmd+Backspace and Cmd+D stop acting on the whole section from inside a code pane. Undo after switching sections no longer pastes the previous section’s code.

Security

The PHP-execution checksum is keyed with the site salt, so it cannot be recomputed by whoever wrote the row; existing blocks keep working and are re-keyed in the background. The licence and update channel verifies TLS certificates and rejects package URLs that are not HTTPS on the licence host.

Free, with licensed updates

Every feature works without a licence key; nothing is gated. A licence buys automatic updates and support. Security releases reach every install regardless, through a separate channel — see SECURITY.md.

Going back

Reinstall v2.8.1. The database stays at schema 1.2, which is expected and harmless. PHP-enabled blocks strip their tags until re-saved. Detail in README.md under “Going back from 3.0.0”.

Permalink

Core Forms 4.9.0

Core Forms 4.9.0 improves submission reliability, spam protection, payment validation, and the WordPress admin experience.

  • Fixes reCAPTCHA and math-captcha validation, draft-save protections, and sensitive template-field access.
  • Preserves form HTML when saving from other tabs and prevents submission deletion from touching unrelated post metadata.
  • Recomputes calculated payment amounts on the server, reports failed submission writes, and preserves uploads without JavaScript.
  • Makes activation safer, improves duplicate prevention and GDPR erasure, and adds submission indexes and diagnostic tools.
  • Adds searchable settings sections, accurate unsaved-change indicators, consistent borders and colors, and accessible copy controls.
  • Improves Commerce navigation and activity, form-builder toolbar states, and submissions filtering.
  • Repairs standalone URL-base changes and shows URL controls only when fullscreen mode and standalone publishing are enabled.

Requires WordPress 6.4+ and PHP 8.1+. Tested with WordPress 7.1.

Validation: 336 unit tests, PHPStan, JavaScript lint, generated-asset checks, package integrity and PHP syntax checks, plus local browser verification.

Read the Core Forms 4.9 release post.

Permalink

GT Page Blocks Builder 2.8.1

Security release. Update before anything else.

Privilege escalation in the block preview. PHP in a Page Block no longer runs for users who can merely edit the post. The builder’s preview endpoint is reachable by anyone with edit_post — an Author, or a Contributor on their own draft — and it executed the section’s PHP after deriving the content checksum from the very content it was about to run, so the check was satisfied by definition. On any site that had turned PHP blocks on, that left the site-wide constant standing alone as the only gate. Running PHP in a preview now requires administrator access, and everyone else previews with the tags stripped and a note saying so rather than silently different output.

The update channel verifies certificates again. It was requesting with sslverify off, and the server’s reply supplies the package URL WordPress downloads and installs a plugin from, so anything able to answer as the licence server could have installed arbitrary code. Certificates are now verified, the request goes through wp_safe_remote_post(), and any package, url or homepage pointing somewhere other than the licence server’s own host is discarded rather than followed. A host with a genuinely broken CA bundle can opt out per-site with GT_PB_LICENSE_INSECURE. The changelog the update screen renders is escaped before display.

The plugin declares what it needs. Requires PHP: 8.1, Requires at least: 6.0, a licence and a text-domain path. It previously declared none, so WordPress offered the update to sites that would fatal on it, and the update payload separately claimed PHP 7.4 while the code has needed 8.1 since 2.7. A site below 8.1 now gets an admin notice naming the versions instead of a white screen. Update URI is set, so the plugin can only ever be updated from its own source.

The licence screen is reachable. It is registered under the Page Blocks menu, but the Plugins row action and both admin notices linked to options-general.php, a screen that does not exist.

Also: the preview endpoint checks the post type, matching the builder; and the GPLv2 text the header declares now ships with the plugin.