* Added admin shell options to hide the notifications panel and the top toolbar
- New Menu setting “Hide notifications panel” removes the notifications bell and inline panel from the main menu sidebar
- New Theme setting “Hide toolbar” removes the complete top toolbar from the classic admin shell
- Admin Framework is unaffected; a mobile menu toggle remains available when the toolbar is hidden
* Added ability to disable the uiXpress theme (classic shell and frontend toolbar) on specific URLs or URL patterns
- New General setting “Disable theme on URLs” accepts path or query substrings such as /page-slug/ or ?bricks=run
- Matching is case-insensitive against the current request path and query string
- Useful for avoiding conflicts with front-end page builders; Admin Framework is unaffected
* Fixed white-label text replacement so it applies consistently across the admin
- Replacements now cover gettext context variants, admin menu titles, plugin Name/Author/Description fields (modern Plugins page, classic plugins list, and updates), and all uiXpress Vue apps via wp.i18n
- Find/replace uses substring matching on both PHP and JavaScript paths
* Fixed conflict with bitforms where it's styles were bleeding into the admin menu increasing size of images
* Stopped blocksy css bleeding over into the media library (classic) and stopping thumbnails from showing
* Added GitHub settings sync for versioning and sharing uiXpress configuration across sites
- New Sync category in uiXpress settings to connect GitHub, choose repository, branch, and JSON file path (default uixpress/settings.json)
- OAuth sign-in through the uiXpress GitHub broker; access tokens are stored encrypted in a dedicated option and are excluded from normal settings export/import
- Pick which settings to include from a catalog grouped like the settings screen (General, Theme, Admin Framework, Login, Dashboard, Security, and more); sensitive keys such as license, remote site credentials, analytics secrets, and TurnStyle secrets never leave the site
- Manual Push uploads the selected settings manifest to GitHub; Pull applies only the managed keys from the remote file
- Push detects remote changes and requires a Pull first when the file SHA no longer matches the last known baseline
- Optional automatic sync runs scheduled Pull-only updates at 15 minutes, 30 minutes, hourly, twice daily, or daily
- Create a new GitHub repository from the settings UI; browse repositories and branches after connecting
- Status panel shows connection details, remote file availability, last sync result, local drift, and recent activity
- REST endpoints under uixpress/v1/settings-sync for status, OAuth, configuration, repositories, branches, push, and pull (manage_options)
- Multisite-aware storage and cron on the network config site; concurrent sync operations are serialized with a short-lived lock
- Extensible via uixpress/settings_sync/catalog and uixpress/settings_sync/protected_keys filters
- Added PHP and frontend regression coverage for manifest validation, sync helpers, and service behavior
* Fixed issue with modern user management where the user details page was not loading
* Restyled user details on modern user management
* Added uiXpress Dark Engine for automatic dark mode on classic WordPress admin pages
- Replaces the previous Magic Dark Mode invert-filter approach with CSSOM-based color conversion scoped to #wpcontent
- Activates automatically when dark mode is enabled on native wp-admin screens; uiXpress chrome (menu, toolbar, custom pages) keeps its native Tailwind dark theme
- Neutral backgrounds, borders, and text map to the active Theme Designer base scale; chromatic colors retain their hue
- Reads plugin and theme stylesheets (including @import layers and adoptedStyleSheets), inline styles, and computed light surfaces, then injects scoped override rules
- Handles dynamically added content via DOM observers, CSSOM hooks, and incremental surface rescans for late-loaded styles and overlays
- Isolation zones (.uipx-normalize, .uixpress-isolation) are excluded so uiXpress components are never rewritten
- Dedicated overlay and TinyMCE styles for Gutenberg popovers, modals, dropdowns, and the classic editor when portaled outside #wpcontent
- Interactive states (hover, active, focus, checked) are darkened with appropriate specificity; text contrast is corrected when backgrounds become too dark
- Session-scoped page and stylesheet caches in sessionStorage speed up repeat visits; caches invalidate on theme or settings changes
- Removed per-page Magic Dark Mode opt-in; dark mode now applies consistently across all classic admin screens when enabled
- Added npm run test:dark-engine regression suite for color conversion, scoping, caching, and restore behavior
* Added new custom dashboard cards on the Overview and Analytics tabs
- Quick Actions: capability-aware shortcuts for creating content, uploading media, moderating comments, viewing the site, and opening settings
- Pending Updates: actionable list of core, plugin, and theme updates with version details, a check-for-updates action, and links to the built-in WordPress updates screens
- Comment Moderation: pending comment queue with count badge and recent items awaiting approval (independent of the dashboard date filter)
- Recent Activity: compact audit trail of latest admin actions when Activity Logger is enabled (requires manage_options)
- Top Events: analytics card showing the most common on-site interaction events (clicks, scroll depth, form submissions, etc.) when uiXpress Analytics is enabled
- Overview cards are ordered with actionable items first; admin-only cards use capability checks so they are hidden from users without the required permissions
- Pending Updates links use classic wp-admin destinations (update-core.php, plugins.php, themes.php) rather than the admin framework updates route
- Added REST endpoint uixpress/v1/content-stats for post-type status counts (publish, draft, pending, scheduled, trash)
- Shared useUpdates composable moved to app/src/composables/useUpdates.js for reuse across dashboard and admin framework
* Added per-user dashboard layout customization
- Customize mode on the Overview and Analytics tabs for drag-to-reorder, drag-to-resize, and hide/show cards
- Card order, width, and visibility are saved per user via REST endpoint uixpress/v1/dashboard-layout
- Hidden cards can be restored from the customize toolbar; Reset layout restores defaults for the active tab
- Available on both the classic dashboard and admin framework dashboard views
* Overhauled Theme settings with a dedicated Theme Designer
- Replaced the flat Theme settings grid with a structured designer for colors, layout, typography, and advanced options
- Organised settings into Behavior, Colors, Layout & shape, Typography, and Advanced sections
- Theme changes apply live across the admin while editing
* Added configurable layout tokens for the classic admin shell
- Spacing density presets: Default, Compact, and Comfortable
- Corner style presets: Default, Sharp, Rounded, and Pill
- Advanced overrides for custom spacing unit and border radius values
- Tailwind spacing and radius utilities now respond to saved theme tokens at runtime
* Expanded theme color presets using Tailwind / shadcn-vue palettes
- Base presets: Zinc, Neutral, Stone, Slate, and Gray
- Accent presets: Indigo, Blue, Violet, Purple, Sky, Cyan, Teal, Emerald, Green, Lime, Yellow, Amber, Orange, Red, Rose, Pink, and Fuchsia
- Presets apply full official Tailwind color scales instead of generated approximations
- Preset cards show full-scale stripe previews inspired by shadcn-vue color pickers
- Advanced section supports manual seed colors and per-step scale overrides
- Selected colour presets are saved and restored via base_theme_preset and accent_theme_preset
* Improved theme variable runtime application
- Extended theme application beyond --uix-base-* and --uix-accent-* to include --spacing-unit and --radius
- Accent color changes now sync --uix-accent-*-rgb values for WordPress admin theme APIs
- Login page receives the same layout and colour variables as the admin area
- Fixed corner style presets having no effect due to scoped --radius overrides in theme CSS
* Added automatic REST nonce refresh for the main admin app
- New uixpress/v1/rest-nonce endpoint returns a fresh wp_rest nonce for the current session
- lmnFetch proactively refreshes stale nonces and retries once after security token failures
- Background timer and tab visibility checks keep long-lived admin sessions working without a page reload
- REST nonce refresh endpoint requires a matching Origin or Referer host, is rate-limited per user and IP, and returns Cache-Control: no-store
* Admin framework wp-admin redirect safeguard (beta)
- Users with the manage_options capability are never redirected from wp-admin to uix-admin
- The Administrator role and admin users are stripped from redirect settings on save and cannot be selected in settings
* Added Plugin Update Protector
- Optionally retains the previous plugin version after updates for one-click rollback
- Automatically detects immediate fatal errors and restores the known-good version
- Covers manual, automatic, bulk, REST, and ZIP replacement update flows
- Emails the WordPress administrator when an automatic rollback is attempted
- Stores protected copies in private storage outside the public web root
* Improved plugins page search and repository browsing
- Installed plugin searches with no matches now offer to search the same term in the WordPress plugin directory
- Plugin repository opens in the main detail panel instead of a flyout drawer, matching the admin framework layout
- Repository search terms are preserved when opening plugin details and returning to results
* Added faster navigation between modern uiXpress admin pages
- Dashboard, posts, media, users, comments, plugins, settings, Menu Creator, Activity Log, Database Explorer, Role Editor, and Admin Notices can switch without a full page reload
- Page scripts and styles are loaded on demand to keep the initial admin bundle lightweight
- Browser back and forward navigation, page titles, menu highlighting, and post-type context stay synchronized
- Added a subtle page-content transition with reduced-motion support
- Native WordPress screens such as the block editor, Site Editor, and Customizer continue to use full page loads
* Improved PHP performance and memory usage across frontend requests
- Reworked backend bootstrapping so admin, REST, AJAX, and cron services load only in the request contexts that need them
- Reduced the measured uiXpress frontend bootstrap memory by approximately 49%, while loading 77 fewer PHP files and classes
- Deferred WordPress plugin, theme, update, and list-table dependencies until their management features are used
- Reduced logged-in frontend toolbar work by skipping admin-only plugin scans, menus, post types, MIME types, theme settings, and capability payloads
- Activity logger services now load only when activity logging is enabled
- Successful analytics table checks are cached to avoid repeated database schema queries
- Preserved custom login routing, SEO metadata, frontend analytics, collaboration, admin framework routes, REST endpoints, and scheduled cleanup tasks
* Corrected Plugin Performance reporting and rankings
- Plugin rows no longer present the shared PHP process peak as memory owned by each plugin
- The overview reports the page process peak once instead of summing overlapping values
- uiXpress now records direct lifecycle checkpoints for autoloading, app construction, initialization, and asset enqueueing
- Memory diagnostics distinguish retained bootstrap growth, observed process growth, and PHP allocator-reserved memory
- Relative impact rankings now use a weighted share of execution time, attributed database queries, and delivered asset size
- Asset impact includes only queued or printed scripts, styles, and their dependencies instead of every registered asset
- Database queries now belong to one nearest plugin caller, excluding profiler and WordPress dispatch frames
- Query totals report the global post-plugins-loaded observation window instead of summing overlapping plugin counts
- Query fingerprints, source files, and originating hooks are available for more reliable diagnostics
* Reduced database query overhead
- Consolidated migration checks and cached settings reads with blog-scoped multisite isolation
- Reduced the measured warm public uiXpress bootstrap from three database queries to one without a persistent object cache
- Replaced repeated activity and analytics table checks with versioned schema readiness markers
- Batched activity writes in retry-safe chunks and converted analytics aggregation to transactional set-based queries
- Cached analytics settings per request and combined comparison, event, user, and media counters
- Reduced dashboard, user, media, and analytics counter queries while preserving existing response formats
- Added a one-request admin framework bootstrap with automatic fallback to the existing endpoints
- Replaced global object-cache flushes with targeted uiXpress repository invalidation
* Refined and standardised UI across several areas of uiXpress
* Fixed checkboxes not visually showing as checked
* Added WordPress multisite support for network-activated installs
- uiXpress configuration menu (Settings, Menu Creator, etc.) is only shown on the primary network site
- Network-managed subsites inherit settings and Menu Creator configs from the primary site
- Direct access to uiXpress admin pages on subsites redirects to the primary site
- Settings and menu writes are blocked on network-managed subsites
* Improved built-in analytics for WordPress multisite subsites
- Analytics tables are bootstrapped on frontend tracking, not only on admin visits
- User analytics dashboard counts subsite members only on multisite
- Analytics dashboard API calls always use current site data (ignores remote site switcher)
* Fixed custom base and accent theme colors not applying outside the settings page
- Theme colors are now applied as inline CSS variables on the document root, matching the settings page behaviour
- Prevents `theme.css` (loaded in the admin footer) from resetting custom color scales back to defaults on other admin pages
* Fixed style conflict with radio inputs where selected items appeared unclickable.
* Added lots of extra icons for the shortcuts icon select
* New admin framework released in beta.
* Settings storage moved from database to file-based JSON
- Non-sensitive uiXpress settings are now stored in `{uploads}/uixpress/settings.json` instead of the `uixpress_settings` option
- Sensitive credentials remain in the database only: license key, instance ID, Google Analytics service account, Turnstile secret key, and remote site app passwords
- Existing installs are migrated automatically on upgrade; no manual action required
- If the uploads directory is unavailable or not writable, settings fall back to full database storage until file access is restored
* Menu Creator storage moved from custom post type to file-based JSON
- Custom admin menus are now stored in `{uploads}/uixpress/menus.json` instead of the `uipx-menu` post type
- Existing menus are migrated automatically on upgrade; legacy CPT posts are removed after a successful migration
- New REST API: `uixpress/v1/menus` replaces `wp/v2/uipxmenus` for Menu Creator CRUD
- Published menus are injected on admin page load, removing paginated REST fetches and the localStorage cache-key system on every admin request
- Sidebar refreshes after edits via `uixpress/v1/menus/published` when menus are saved or deleted
- Emergency fallback: menu data is mirrored to the `uixpress_menus_backup` option whenever the file is written
- Security: `{uploads}/uixpress/` is protected with `.htaccess` and `index.php`; Menu Creator CRUD requires `manage_options` with REST nonce verification; published menu reads require an authenticated session; menu item URLs and metadata are sanitized on write and on API output
* Fixed woocommerce layout / styling issues.
* Modern plugin manager: batch selection and bulk actions
- Multi-select in the installed plugins sidebar with select-all, shift-click range select, and a floating bulk action bar
- Row checkboxes are right-aligned and revealed on hover; selected plugins keep their checkbox visible
- Plugin list rows show version number with an "Update available" label when an update is pending (author removed from the list view)
- Bulk activate, deactivate, update, enable/disable auto-updates, and delete via sequential calls to existing REST endpoints
- uiXpress is protected from bulk deactivate and delete; plugins with unmet dependencies are skipped during bulk activate
- Summary notifications report success, failure, and skipped counts after each bulk operation
* Fixed layout issues on the widgets page.
* Fixed style conflicts with block editor and etch
* Settings storage moved from database to file-based JSON
- Non-sensitive uiXpress settings are now stored in `{uploads}/uixpress/settings.json` instead of the `uixpress_settings` option
- Sensitive credentials remain in the database only: license key, instance ID, Google Analytics service account, Turnstile secret key, and remote site app passwords
- Existing installs are migrated automatically on upgrade; no manual action required
- If the uploads directory is unavailable or not writable, settings fall back to full database storage until file access is restored
* Menu Creator storage moved from custom post type to file-based JSON
- Custom admin menus are now stored in `{uploads}/uixpress/menus.json` instead of the `uipx-menu` post type
- Existing menus are migrated automatically on upgrade; legacy CPT posts are removed after a successful migration
- New REST API: `uixpress/v1/menus` replaces `wp/v2/uipxmenus` for Menu Creator CRUD
- Published menus are injected on admin page load, removing paginated REST fetches and the localStorage cache-key system on every admin request
- Sidebar refreshes after edits via `uixpress/v1/menus/published` when menus are saved or deleted
- Emergency fallback: menu data is mirrored to the `uixpress_menus_backup` option whenever the file is written
- Security: `{uploads}/uixpress/` is protected with `.htaccess` and `index.php`; Menu Creator CRUD requires `manage_options` with REST nonce verification; published menu reads require an authenticated session; menu item URLs and metadata are sanitized on write and on API output
* Fixed woocommerce layout / styling issues.
* Modern plugin manager: batch selection and bulk actions
- Multi-select in the installed plugins sidebar with select-all, shift-click range select, and a floating bulk action bar
- Row checkboxes are right-aligned and revealed on hover; selected plugins keep their checkbox visible
- Plugin list rows show version number with an "Update available" label when an update is pending (author removed from the list view)
- Bulk activate, deactivate, update, enable/disable auto-updates, and delete via sequential calls to existing REST endpoints
- uiXpress is protected from bulk deactivate and delete; plugins with unmet dependencies are skipped during bulk activate
- Summary notifications report success, failure, and skipped counts after each bulk operation
* Fixed layout issues on the widgets page.
* Fixed style conflicts with block editor and etch
* Custom dashboard: dashboard tab order setting now includes per-tab visibility (show/hide); hidden tabs are excluded from the dashboard tab bar (with a fallback if all would be hidden)
* Custom dashboard: new "Dashboard post types" setting (multi-select); drives Recent content, Scheduled Content, and Recent comments. Empty selection defaults to Posts only
* Added REST endpoint `uixpress/v1/dashboard-comments` to return comments filtered by selected post types for the dashboard Recent comments card
* Improved plugin ZIP replacement flow in the modern plugin manager
- Uploading a ZIP for an already installed plugin now asks for confirmation before replacing files
- Confirmation modal shows useful plugin metadata from the plugin root header, including version and requirements, to help validate the replacement
* Fixed plugin active status after ZIP replacement
- Replaced plugins that were active now correctly remain marked active after a successful replace/reactivation
* Fixed custom uiXpress plugin name in the modern plugin manager
- The "Rename uiXpress" white-label setting now updates the uiXpress plugin name in the modern plugin list and detail view
* Fixed conflict with solid security plugin
* Fixed Gravatar / email hashing on non-secure HTTP URLs
- encodeToHash used Web Crypto subtle.digest, which is unavailable outside secure contexts (HTTPS or localhost)
- Sites on plain HTTP (e.g. Local .local domains) threw "Cannot read properties of undefined (reading 'digest')"
- Added a SHA-256 fallback so the same hex hash is produced when SubtleCrypto is missing
* Fixed intermittent modern post list pagination (e.g. page 2 on Pages) returning redirects or failing to load
- The hidden data endpoint admin.php?page=uixpress-posts-data overwrote global $pagenow too early (on plugins_loaded), so WordPress could resolve the wrong admin screen hook
- Validation and edit-screen context now run at the start of render_page() after routing is correct
- Permission check uses the requested post type’s edit capability (e.g. edit_pages for pages)
- fetchPostsData always sets page=uixpress-posts-data last so a duplicate page query arg cannot override the menu slug
* Improved button contrast and seperation in dark mode
* Refreshed menu icons
* Improved hover submenu stability with grace-area pointer intent
- Added pointer-intent submenu handling so slight diagonal cursor drift does not immediately close hover submenus
- Submenu bounds are recalculated during viewport resize/scroll while open for more reliable intent checks
- Prevented accidental submenu switching when crossing neighboring parent items while still moving toward the active submenu
* Fixed submenu hover state leaking between menu sections
- Hover state is now scoped per menu context (expanded, shortcuts/favorites, minimized)
- Prevents the same link from opening in both the main menu and shortcuts at the same time
- Keeps hover behavior isolated to the section currently being interacted with
* Added dashboard tab reordering in Settings
- New setting: Settings > Dashboard > Dashboard tab order
- Lets users rearrange dashboard category tabs and persists order to dashboard_tab_order
- Dashboard tab toggle now renders categories using the saved custom order
* Fixed various wp-toolbar issues