What changed in Enhance from 8 to 12

89 releases numbered after 8.5.4 up to and including 12.25.8, stable releases only. 8.5.4 and 12.25.8 are the newest stable releases of 8 and 12 we track; this page follows them as new ones ship.

368 changes across 89 releases · 3 landed on more than one version

Added 76

12.25.1

  • getGlobalInstallableApps and getInstallableApps endpoints now return OpenClaw as a supported application

12.25.0

  • 3rd party DNS hooks added to Integrations
  • Default DMARC added for all new zones with policy set to p=none, editable per website or as a platform DNS zone template
  • installServerRole API endpoint has an additional parameter to disable the role on installation
  • Disabled server roles are automatically enabled when a customer is subscribed to a dedicated plan using that server or role
  • New getPhpMyAdminWebsiteSSOUrl endpoint added which does not require a specific database name

12.24.0

  • Customers can now enable the ability to edit cron jobs with SSH or any other process running under the website container via the developer tools section of the website dashboard
  • OpenClaw is now available as an installable application via the apps tab of the website dashboard
  • OpenClaw toolkit can add API provider keys, rotate tokens and configure device authentication
  • Packages can now be configured to restrict the installable applications

12.23.0

  • Node.js websocket proxy support
  • Inode resource limit per website as a package setting that can be overridden on a per website basis
  • Copy button added to domains table

12.22.0

  • Optionally install the PostgreSQL role to servers within your cluster and provide PostgreSQL hosting to your customers
  • pgsql and pdo_pgsql PHP modules are enabled automatically if a PostgreSQL database is created by the customer

12.21.1

  • Unix username generation for numeric domains of more than 8 characters in length

12.21.0

  • PHP extension manager now allows enabling any extension built or installed within the global extension directory for the chosen PHP version
  • Developer tools section now lists built-in PHP extensions in addition to optional extensions

12.20.1

  • An optional description has been added to token creation from CLI

12.19.0

  • Service websites can have their PHP version changed with the bulk update tool
  • Onboarding help card can now be permanently dismissed across all devices

12.18.0

  • Joomla one click installer that automatically makes Joomla available to users when 'Allow software installer' is enabled on a package

12.17.0

  • Roundcube SSO support
  • Option to overwrite conflicting files when unzipping with the file manager

12.16.0

  • Ability to clone to staging from the website dashboard hero section
  • Database sizes now show in database listing

12.15.0

  • Restore individual files from an Enhance website backup
  • Limit swap usage under system resource limits

12.14.0

  • Server specifications now shown in master organisation servers dashboard
  • Customers with dedicated subscriptions can now view server specifications, load, memory and swap usage
  • Traditional Chinese (Taiwan) locale (Beta)
  • Decommission and delete options are now accessible for an offline server

12.13.2

  • Connectivity diagnosis for servers which are unreachable from the control panel server
  • Additional error logging for S3 errors

12.13.0

  • Users on per-server Roundcube can now change their password in the Roundcube UI
  • PHP 8.5 support
  • S3 credentials are automatically synchronised to servers on installation of the application or email role
  • UI to pre-install custom WordPress plugins from a URL

12.12.0

  • DS/CAA records can now be added to DNS zones and DNS templates
  • Default TTL setting can now be set under Platform Settings
  • LSAPI_CHILDREN can now be limited via the website overrides panel when the web server is OpenLitespeed/Litespeed
  • Backups can now be disabled on a website via the website overrides panel
  • WordPress username can now be an email

12.11.10

  • Display warnings in UI when I/O and IOPS limits are set too low on package level and per-website override
  • Add Hanken Grotesk Google font
  • Increase timeout for manual Let's Encrypt issuance

12.11.0

  • Add Node.js support

12.10.6

  • Additional validation of MySQL database names

12.10.0

  • Ability to download/upload an Enhance website backup
  • Azerbaijani language pack (beta)

12.9.8

  • A user's 2FA status is now displayed on the Users page
  • It is now possible to delete a preview domain

12.9.7

  • A reseller can set an upper limit on dynamic mailbox size if their own subscription is unlimited

12.9.3

  • Limit the number of DNS records that can be created per domain on a package level

12.9.0

  • Each server within a cluster now displays the Enhance version it is running

12.8.0

  • Catch-all email addresses
  • Access token IP lockdown
  • Ability to edit roles for existing access tokens
  • Access token management added to ecp CLI tool
  • 'Host' and 'Port' prompts added to the FTP Login credential card

12.7.0

  • Master organisation can restore backups of websites which were permanently deleted if they were backed up using the Enhance backup role
  • Backups using the Enhance backup role now contain DNS data

12.6.0

  • Reinstate backup failure logging to the activity log for customers on version 12.x
  • Generate a descriptive error when attempting to create a central webmail website with no database role installed
  • Add mitigation for incompatible collations when cloning a website from a server with MariaDB to a server with MySQL
  • SuperAdmin can now set admin lockdown via API to allow for automation with bearer token

12.5.1

  • Additional guidance provided on licence settings page when licence status is Unknown

12.5.0

  • Ability to restrict access to the Master Organisation by IP address for interactive login and SSO

12.4.0

  • Setting to enable email server stickiness to default the Email role for a website to be placed on the same server as the Application role if the Email role is installed

12.3.0

  • createWebsite endpoint now installs WordPress and any preinstalled plugins and themes if specified on the customer's hosting package
  • New override for apache2 systemd unit to mitigate problem with large file uploads when mod_security is enabled

12.2.0

  • Hebrew language pack
  • Support for legacy PHP 5.2 - 5.5
  • Added Restart=always to lshttpd systemd override

12.1.0

  • Support for sending custom access-Host-Allowed-Origin header from control panel API
  • WordPress plugin installation API can now accept a URL for installation of plugins not registered with WordPress.org
Changed 175

12.25.8

  • Updated Openclaw installation process to be compatible with the latest Openclaw release

12.25.5

  • Improved network isolation for ephemeral containers
  • Added additional restriction on website backup upload for service websites

12.25.4

  • cPanel importer now tolerates numeric values for 'ssl' and 'port' in cPanel userdata domain files
  • WordPress installation via wp-cli now prefers the zip archive to mitigate an issue with extraction of long path names from tar files

12.25.2

  • Dev dependencies are now removed before running the composer install command when installing the wp-cli login package as part of the ecp-core postinst script

12.25.1

  • Search login on Customers page moved from UI code to API to improve performance on larger clusters
  • Improved phpMyAdmin error reporting
  • Overrides back heading now contains the primary domain of the website being edited

12.25.0

  • Improved Danish translations
  • New Quick Links section added for website dashboard
  • A reseller subscription recalculation is now triggered after a soft deletion of a customer org
  • orchd, appcd and appd now only start if started by systemd
  • orchd will no longer start as root
  • Improved email transfer logic and failure handling

12.24.0

  • Numeric progress indicator added to file manager upload

12.23.0

  • PostGIS and PGVector now enabled by default on new PostgreSQL installations
  • Automatically recalculate subscription on cloning failure
  • Default post_max_size and upload_max_filesize now 1000M if no specific limit is configured
  • Explicitly set WordPress site url and home when using search replace to mitigate object cache issue on cloning
  • Improved Hebrew and Portugese translations
  • Increased timeout for email role migration
  • Primary domain now always listed first on domains table
  • wp-admin button on the website dashboard now defaults to the installation in public_html ahead of any addon domains

12.22.2

  • Increased timeout for WHM API client to 1 hour to improve cPanel import from remote server when dealing with very large accounts
  • Improved error messages for website cloning and push-live
  • Improved cleanup of mysql.db table when a MySQL database is removed
  • Panel lists now use brand accent colour

12.22.1

  • Increased RPC timeout for application role transfer

12.22.0

  • Increased email transfer RPC timeout
  • Additional prompt for resellers to set a control panel domain when creating a customer, if no control panel domain has been set
  • phpMyAdmin button added to database listing
  • In the file manager, document roots are now highlighted by a 'globe' icon
  • Connection guidance added to database management page for end users
  • MariaDB LTS initial installation now explicitly sets utf8mb4 server character set in my.cnf
  • Efficiency and performance improvements to internal APIs
  • dump.rdb (Redis persistent data store) now automatically excluded from website cloning
  • Improvements to backup transfer guard logic when attempting new website backups
  • Roundcube version bumped to 1.6.16
  • Removing all database privileges for a user means the user is no longer listed under the database
  • Improved error messages for remote MySQL connection failure
  • Added database size to backup listing
  • Container IP now automatically allowed for new MySQL users where the application and database roles are on the same server
  • Plesk importer now handles backups with missing 'directories' param
  • MySQL databases now listed on the package subscription card where the resource is set to unlimited

12.21.6

  • Hide 'mailq' and 'postqueue' binaries from customer container

12.21.3

  • End user must now supply subscription ID when cloning to a new website via API

12.21.2

  • Global backup settings are now re-applied on installation of a new Backup role
  • Expired snapshot cleanup runs less frequently and on a separate scheduler

12.21.1

  • Increased Let's Encrypt initial connection timeout
  • Improved Polish language packalso in12.14.112.13.0
  • Altered RPC keepalive strategy for transfer of backup data between servers
  • Built in PHP extensions displayed in website dashboard now include compulsory extensions loaded at runtime in addition to those compiled in to PHP

12.21.0

  • Incompatible extensions are now disabled automatically when changing PHP version
  • mod_security is now explicitly disabled for the per-server Roundcube installation on Apache and Nginx web servers
  • New backups are no longer started during a backup migration to improve transfer performance
  • Cleanup of expired snapshots is no longer performed during a backup migration to improve transfer performance
  • Improved efficiency and speed of expired snapshot cleanup
  • MySQL 8.4 is now the default version when MySQL is selected due to 8.0 EOL

12.20.1

  • Supported Roundcube version has been updated to 1.6.15
  • File manager proxy configuration is automatically regenerated when a server's primary IPv4 address is updated in the Enhance user admin interface

12.20.0

  • Per-server Roundcube now auto-updates to the latest supported version, currently 1.6.14

12.19.0

  • Default PHP version for Central Roundcube and phpMyAdmin is now 8.3
  • Joomla installation now allows 10 character passwords
  • Swap limit system resource can now be set to 0

12.18.0

  • Default PHP version for new websites and packages is now 8.3
  • Underscores are now valid in NS names

12.17.0

  • Improved Vietnamese language pack
  • Overriding website memory limit to unlimited is now applied immediately

12.16.1

  • Dovecot reload after adding a domain is now debounced to prevent excessive reloading when a large amount of domains are added in a short period of time

12.16.0

  • Website size now includes home directory, databases and emails

12.15.0

  • S3 backups are now tagged with 'S3' to indicate that granular file restores are not supported
  • IMAP module enabled by default on PHP 8.4 and 8.5 for new and existing websites
  • imagick module enabled by default on PHP 8.5 for new and existing websites

12.14.3

  • Subscription recalculation is now forced after successful website clone
  • Cloning process only checks for database resource on the destination package where databases exist on the source website
  • Improved fault tolerance for automated o/s package installation (apt)

12.14.2

  • Check /usr/bin/composer for validity on installation of ecp-core and re-download composer if not valid
  • Apply stricter RPC timeouts to DNS sync queue to prevent slow queue processing when some DNS servers in the cluster are offline
  • Improve miscellaneous UI elements

12.14.1

  • Application role installation now explicitly installs the mariadb-client package if the database role is not installed
  • Database role transfer now checks mysql client version for appropriate command line arguments when the transfer is initiated by a standalone app server with no database role installed

12.14.0

  • Backup settings are now explicitly re-applied to servers on role installation and reinstallation
  • Migration of application role to a server where the email role is already placed now explicitly applies the local and remote setting per domain from the control panel database
  • WordPress SSO plugin is now downloaded and cached at a server level for faster activation and avoidance of Github API rate limits
  • Reduced API calls from servers page for better performance
  • Improved performance and reduced memory usage of website DNS resolution check

12.13.2

  • On OpenLiteSpeed install, systemctl daemon-reload is retried multiple times

12.13.0

  • When a container is restarted, the previous virtual interface device is now explicitly taken down in case another process is holding open the network namespace
  • Improved Turkish language packalso in12.12.0
  • Improved Spanish language pack
  • Global webmail has been positioned as the secondary option under the advanced dropdown

12.12.0

  • Default TTL is set to 1400 sec and applies only to new websites
  • When creating a new record without a specified TTL, it now mirrors the SOA TTL
  • Improved NL language pack
  • PHP FPM settings now hidden from website overrides panel when the web server is Litespeed/OpenLitespeed
  • Mariadb installation now uses alternative apt repository
  • Increased timeouts for Let's Encrypt provisioning for automatic and manual requests

12.11.10

  • MariaDB repo config no longer uses mariadb install script
  • Improve ghost button consistency
  • Update IOPS limit calculations
  • Redesign logs page
  • Improve Turkish language pack

12.11.8

  • Reduced memory usage of appcd service during backup runs
  • System MTA is explicitly installed and configured during control panel initialisation

12.11.7

  • German translation improvements

12.11.6

  • libsasl2-modules package is now specifically installed alongside Postfix MTA
  • Support user can no longer change screenshot settings
  • Master organisation collaborator can no longer view activity log
  • Tighter rate limiting for 2FA

12.11.5

  • External application names in Openlitespeed web server are now unique when using Node.js
  • Improved validation of collaborator access level

12.11.4

  • Deleting an addon domain now also removes the DNS zone
  • Improved Ukrainian language pack
  • Improved tag functionality on subscriptions
  • Inline logs and general UI improvements to PHP section

12.11.2

  • Invited master organisation support and business users can no longer update the licence key

12.11.0

  • Improve performance for how containers are started
  • Improve simplified Chinese language pack
  • Improve Portuguese language pack

12.10.6

  • Reduced concurrency for deletion of expired backup snapshots to reduce load on backup servers with limited I/O

12.10.3

  • Improved image handling and detection for SVG images in branding settings

12.10.0

  • Improved Norwegian language packalso in12.3.0
  • Pre-existing mailbox directory is no longer a fatal error if owned by the website user

12.10.1

  • Downloadable backups now skip unreadable files
  • Document root permissions are now checked and reset after backup upload
  • Home directory data is no longer copied when downloading email-only backup where the app and email roles are placed on the same server

12.9.9

  • Enhance now installs the latest version of LiteSpeed (v6.3.4) on installation

12.9.7

  • Improved startup time of appcd for servers with a high website count (5000+)
  • Increased RPC timeout for post migration success cleanup

12.9.4

  • Cloudflare integration now explicitly sends quotation marks around TXT record
  • Onboarding of new servers to an existing cluster will ignore any ipv6 records in DNS
  • Additional guidance in ecp join error output

12.9.3

  • Increased timeouts for wp-cli, composer and ioncube loader install during ecp-core package postinst script

12.9.0

  • PHP SAPI now starts on demand by default to reduce memory usage from idle websites, reducing idle RAM usage from approximately 60mb to 2mb
  • Staging domains are now marked as 'noindex' by default for newly added websites
  • Improvements made to Hebrew language pack
  • php-error.log no longer backs up
  • Session cookie now sends SameSite=none when custom CORS is enabled
  • Cron jobs handling improved for cases with blank lines or environment variables in the user's crontab when edited from the UI

12.7.1

  • Email role transfer RPC timeout increased to 1 day

12.7.0

  • Website restore logic improved for customers using the Enhance backup role
  • Disaster recovery logic improved for customers using the Enhance backup role
  • Email and mailbox logic moved to the application server (appcd) in preparation for future portable backup and CLI restore functionality
  • Norwegian language pack improved
  • Polish language pack improved
  • WordPress toolkit can now handle deprecated warnings injected inline from plugins such as Elementor
  • Error messages for RPC connectivity improved

12.6.1

  • Automatic and manual backups will now retry the rsync operation if it fails on the first attempt
  • Backup process is now less sensitive to hard disk quota issues on the source server
  • No S3 settings is now logged to the trace log rather than the error log to avoid excessive log noise
  • Improvements to wp-cli cache warmer utility
  • Resource calculation endpoint now saves the result to the database

12.6.0

  • Move logic for management of local .my.cnf file to appcd service for improved performance
  • Check and repair local .my.cnf before each backup or restore operation
  • Hide /var/lib/mysql and /var/lib/docker totally from website containers

12.5.0

  • pt-PT language pack improvements

12.4.0

  • Improved guidance for setting of HELO name

12.3.3

  • Primary domain now appears at the top of the domain selector when creating a new email address
  • appcd-cli list-websites now returns JSON output
  • Custom CORS feature now permits multiple origins
  • A more informative error is given when a reseller or master organisation has no phpMyAdmin domain configured
  • Added port 587 to email client config guidance

12.3.2

  • French language pack improvements
  • orchd service will now wait for initialisation of master organisation before starting internal workers

12.3.1

  • Improved licence check logic in orchd service
  • Website backup restore now removes files which exist on the website but do not exist in the chosen restore point, matching behaviour from versions before 12.0.0
  • Improved pt-BR locale

12.3.0

  • Improved Arabic language pack
  • Improved Ukranian language pack

12.2.0

  • Improved Portugese and Bulgarian language pack
  • CHMOD setting now applies recursively

12.1.0

  • Backup process is now tolerant of the previous snapshot having been manually removed

12.0.27

  • ecp sso now prints an SSO link for the control panel domain in addition to the IP
  • Increased timeout for post migration cleanup activities
Fixed 110

12.25.8

  • Removed automatic device authentication option for Openclaw as this is no longer supported in the latest Openclaw release

12.25.7

  • Regression causing incorrect permissions to be set on document root directories during creation of a new website

12.25.4

  • False error message no longer displayed when a customer package defines preinstalled WordPress plugins and Openclaw is installed

12.25.3

  • Customer stickiness, if enabled, now ignores service websites belonging to that customer when determining placement of a new website

12.25.1

  • cPanel imports now complete when PostgreSQL is enabled on cPanel but not on Enhance by skipping PostgreSQL databases during import
  • phpMyAdmin domain selection for resellers now ignores soft-deleted domains
  • API will no longer accept syntactically invalid '..' in email local part

12.25.0

  • Push live now copies cron jobs
  • Push live now copies IonCube
  • Reseller control panel domain warning

12.24.0

  • Additional improvements to UI domain sorting login on domains tab of website dashboard

12.23.1

  • 401 error no longer returned when attempting to log out all devices from user profile
  • Primary domain now correctly shows at the top of page 1 when listing website mapped domains spanning multiple pages

12.23.0

  • Application installations now adhere to package database resource limits

12.22.2

  • Resolved error when creating PostgreSQL databases under a website beginning with a number
  • Fixed spacing issue on catch-all checkbox

12.22.1

  • PostgreSQL resource count now shows correctly in package resource listing where the resource was set to 0 during initial package creation
  • Mitigation for rsync "link dest" regression in 3.2.7-1ubuntu1.4 package
  • Backup restoration no longer returns a false failure notice when no PostgreSQL server is available

12.22.0

  • Removed onclick and 'manage' dropdown option for preview aliases which cannot be managed
  • UI for resellers no longer attempts to set deprecated 'processes' resource
  • WordPress username update via WordPress toolkit now functional
  • Corrected chowning logic for Litespeed (commercial) virtual host config files
  • SMTP SASL auth now correctly disabled when configuring a smart host with no credentials

12.21.6

  • Improved cleanup of expired "run in customer container" tasks initiated by WordPress/Joomla toolkit to prevent potential task queue overrun

12.21.4

  • Backup destination is now updated on application and email servers when migrating a website that previously had no backup server set to a new backup server

12.21.2

  • Improved handling of expired snapshot deletion where directories are missing read or execute permissions
  • File manager can now handle directories which are unreadable due to file permissions

12.21.0

  • Enabled PHP extensions now persist after server migration
  • Website backup destination is now performed after a successful transfer of the backup role
  • Prevent excessive logging where the per-server Roundcube website has not yet been created

12.20.0

  • Minor UI rendering issues during role installation

12.17.0

  • File manager no longer allows quota bypass
  • Fixed typo on Plesk importer

12.16.0

  • Subscription disk usage now properly counts database and email usage
  • Clone to staging can no longer bypass staging website limit
  • Global smart host is now applied to standalone control panel servers on save

12.15.1

  • Impersonation now persists when a hard refresh is performed in the browser
  • Swap limit now displays correctly on packages created on versions < 12.15.0

12.15.0

  • Database restore can now handle databases which have been dropped from the command line

12.14.3

  • Corrected subscription bandwidth calculation

12.14.2

  • Fix race condition causing a node.js application not to be placed into the correct control group when automatically started via Enhance
  • Remove duplicate API call for memory usage on server management dashboard

12.14.1

  • Incorrect CPU core count on virtual machines where cores are presented by the hypervisor to the guest as separate physical CPUs

12.14.0

  • Editing IP in connectivity check modal no longer resets the IP when the existing IP is totally removed

12.13.2

  • Fix for a cPanel import where home dir on the cPanel side is non-standard

12.13.1

  • Exclude .well-known/acme-challenge from proxy when the root of a domain is proxied to a Node.js app on all web server kinds

12.11.10

  • Fix IO bandwidth being applied in the wrong order of magnitude (gigabytes instead of megabytes)

12.11.8

  • Double search/replace on WordPress site URL during cloning or push-live when perform search and replace is selected
  • Failure to update WordPress site URL during website cloning is now non-fatal

12.11.7

  • Resellers can no longer create customers via the API without the resellerSubResellers allowance on their own package

12.11.6

  • Reinstated missing context menu on database user listing with table row height fix

12.11.5

  • White page bug in UI when managing control panel websites

12.11.4

  • App role migration reinstates Node.js deployments
  • Prevent system actions by Support user
  • API no longer allows % in email username
  • Cleanup of created databases and database users if failure occurs during the creation phase
  • Download email data no longer shows on dashboard where no email server exists

12.11.2

  • appinit now sets PHPRC environment variable when starting lsphp to prevent loading of custom php.ini from the home dir where it has been imported from another panel

12.11.3

  • Fix UI bug when packages are created by a reseller where the reseller's own package does not support Node.js

12.11.0

  • Fix force https setting to now redirect /api requests when enabled on the control panel domain running Apache

12.10.4

  • Improved validation of pre-hashed mailbox passwords to prevent potential breakage of dovecot user db

12.10.3

  • Added additional Content-Type header for auto reply messages to fix Roundcube display issue

12.10.0

  • Intermittent bug with maildir user creation group ownership

12.10.2

  • UI white screen bug when managing control panel and central webmail websites

12.9.8

  • S3 backup is now tolerant of missing mail directories
  • Moving an application role away from a server whilst leaving the email role behind now removes the user crontab from the source server

12.9.7

  • A reseller can now be downgraded to a non-reseller package if they have previously created and deleted customers

12.9.6

  • appcd process monitor no longer waits for pids it has not explicitly killed
  • Prevention of double slash in nginx SCRIPT_FILENAME env var passed to PHP

12.9.4

  • appinit will clean up orphaned processes that it becomes the owner of due to the original parent process ending
  • It was not possible to remove a domain mapping from a website if another domain existed which ended in the domain to be deleted

12.9.2

  • Fix custom backup restore on S3
  • Fix database failure when restoring S3 full website backup

12.9.0

  • Cron jobs no longer get overwritten when added via the UI if the crontab contained blank lines, comments or environment variables
  • False backup error logging when no primary domain mapping existed on the Application server
  • Process manager interrogation of existing processes

12.7.1

  • UI rendering error on customer management page, email tab
  • Excessive truncation of file size on website backup card

12.7.0

  • Group ID bug in file manager (filerd) service

12.6.1

  • Backup process can now recover if the home directory for the backup user is manually deleted
  • Upgrade from v11 now explicitly sets www-data group ownership on public_html even if it does not match the document root of a mapped domain
  • MariaDB repo download script now forces ipv4 to mitigate an issue with some ipv6 IPs being blocked by MariaDB
  • Mitigation for issue where email and website backup run on separate servers at the exact same time
  • Bandwidth counter (total) rounding error
  • Moving a standalone database role from a decommissioned server did not update the remote SQL settings on the target application server

12.6.0

  • Fix race condition where the local .my.cnf had been modified and website files were restored before databases which prevented a restore of the database
  • Fix incorrect descriptive text for email rate limits in English language
  • Fix system commands in platform update instructions excluded from translation
  • Fix issue backing up databases with massive text rows on some versions of MariaDB

12.5.1

  • SSO no longer requires a hard refresh when a previously expired session existed

12.5.0

  • Incorrect domain sort order on email creation for users of Chrome browser
  • Auto generated invite link was missing :2087 for clusters without a control panel domain configured
  • Prohibited domain UI was incorrectly shown to resellers
  • Plesk importer can now handle generated XML with self-closing tags created by some versions of Plesk

12.4.0

  • Customer and subscription stickiness were incorrectly applied when toggled in the UI

12.3.3

  • Redis status persisted on website migration
  • Ioncube status persisted on website migration
  • Package setting for automatic installation of WooCommerce now working
  • WP plugin list tolerates boolean update parameter in json plugin listing from wp-cli
  • File manager text editor now functional in RTL locales
  • In file manager, files with non-utf8 encoded filenames no longer cause a fatal error, instead any invalid characters are displayed as replacement character
  • Openlitespeed is now explicitly restarted after installation to pick up Enhance systemd override drop-in
  • Openlitespeed is now explicitly uninstalled when changing to another web server type
  • WordPress auto discovery tolerates longer database names from imported websites

12.3.2

  • Intermittent issue with restoring large database tables when using S3-compatible backup system
  • Failure to remove expired snapshots when using S3-compatible backup system

12.3.0

  • Internal filerd token timeout during large website clones

12.2.0

  • Fix for missing /dev/tty device in customer SSH environment

12.0.27

  • Backup destination is now updated on the destination server during application role transfer
Removed 3

12.21.3

  • Ability of collaborator role to add or delete Cloudflare tokens via API

12.21.0

  • Control panel websites can no longer be mapped to a database server

12.10.0

  • Upload limit for file uploads to the Enhance panel
Security 4

12.25.3

  • SVG uploads from resellers and end users are now explicitly checked for Javascript content which might be executed if the SVG file were opened directly in the browser

12.21.5

  • Hide known setuid binaries from website containers to limit attack vectors from compromised CMS or malicious customers targeting local privilege escalation vulnerabilities

12.11.7

  • The list of endpoints accessible to a login session which has not yet completed 2 factor authentication has been further restricted

12.11.1

  • Fix user role permission handling in the control panel API

12 releases in the range carry no categorized changes yet: 12.25.612.24.112.13.312.11.912.10.512.9.512.9.112.6.212.0.2812.0.2912.0.3012.0.26. Their original notes, where the vendor published any, are below.

Original release notes, newest first

The list above is our reading of these notes; the originals from Enhance Hosting Automation are here, one fold per release.

12.25.812.25.8 LatestAI extracted

Enhanced Updated Openclaw installation process to be compatible with the latest Openclaw release. Fixed Removed automatic device authentication option for Openclaw as this is no longer supported in the latest Openclaw release.

View originalPermalink

12.25.7AI extracted

Fixed Regression causing incorrect permissions to be set on document root directories during creation of a new website.

View originalPermalink

12.25.6AI extracted

Enhanced Improved PHP version detection logic for cPanel importer.

View originalPermalink

12.25.5AI extracted

Enhanced Improved network isolation for ephemeral containers. Additional restriction on website backup upload for service websites.

View originalPermalink

12.25.4AI extracted

Enhanced cPanel importer now tolerates numeric values for 'ssl' and 'port' in cPanel userdata domain files, to mitigate recent changes in cPanel. WordPress installation via wp-cli now prefers the zip archive to mitigate an issue in with extraction of long path names from tar files in the current version of wp-cli. Fixed When a customer package defines preinstalled WordPress plugins, a false error message is no longer displayed when Openclaw is installed.

View originalPermalink

12.25.3AI extracted

Security SVG uploads from resellers and end users are now eplicitly checked for Javascript content which might be executed if the SVG file were opened directly in the browser. Fixed Customer 'stickiness', if enabled, now ignores service websites belonging to that customer when determining placement of a new website.

View originalPermalink

12.25.2AI extracted

Enhanced When installing the wp-cli login package as part of the ecp-core postinst script, dev dependencies are removed before running the composer install command.

View originalPermalink

12.25.1AI extracted

Enhanced cPanel imports are now able to complete where PostgreSQL is enabled on cPanel but not on Enhance, by skipping any PostgreSQL databases during the import process. The search login on 'Customers' has been moved from UI code to API to improve performance on larger clusters. Improved phpMyAdmin error reporting. "Overrides" back heading now contains the primary domain of the website being edited. getGlobalInstallableApps and getInstallableApps endpoints now return OpenClaw as a supported application. getInstallableApps returns applications subject to package restrictions. Fixed phpMyAdmin domain selection for resellers now ignores soft-deleted domains. API will no longer accept syntactically invalid ".." in email local part.

View originalPermalink

12.25.0AI extracted

Added 3rd party DNS hooks added to 'Integrations'. Default DMARC added for all new zones. The default policy is set to 'p=none', this can be edited on a per website in Website > Domain > DNS records or as a platform DNS zone template in Settings > Platform > DNS. installServerRole API endpoint has an additional parameter to disable the role on installation. Disabled server roles are automatically enabled when a customer is subscribed to a dedicated plan using that server/role. Enhanced New getPhpMyAdminWebsiteSSOUrl endpoint added which does not require a specific database name (existing getPhpMyAdminSSOUrl endpoint is still functional) Improved Danish translations. New 'Quick Links' section for website dashboard. A reseller subscription recalculation is now triggered after a soft deletion of a customer org. orchd, appcd and appd now only start if started by systemd, to prevent overzealous LLMs starting duplicate copies of appcd. orchd will no longer start as root. Improved email transfer logic and failure handling Fixed "Push live" now copies cron jobs. "Push live" now copies IonCube. Reseller control panel domain warning.

View originalPermalink

12.24.0AI extracted

Added Customers can now enable the ability to edit cron jobs with SSH (or any other process running under the website container) via the "developer tools" section of the website dashboard. OpenClaw is now available as an installable application via the "apps" tab of the website dashboard. OpenClaw toolkit can add API provider keys, rotate tokens and configure device authentication. Packages can now be configured to restrict the installable applications. Enhanced Numeric progress indicator added to file manager upload. Minor UI improvements. Fixed Additional improvements to UI domain sorting login on "domains" tab of website dashboard.

View originalPermalink

12.24.1AI extracted

Enhanced Default RoundCube version bumped to 1.6.17

View originalPermalink

12.23.1AI extracted

Fixed 401 error no longer returned when attempting to "log out all devices" from user profile. Primary domain now correctly shows at the top of page 1 when listing website mapped domains spanning multiple pages.

View originalPermalink

12.23.0AI extracted

It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Added Node.js websocket proxy support. Inode resource limit per website. This is a package setting and can be overriden on a per website basis. Documentation can be found here. Enhanced PostGIS and PGVector now enabled by default on new PostgreSQL installations. Automatically recalculate subscription on cloning failure. Default post_max_size and upload_max_filesize now 1000M if no specific limit is configured. Explicitly set WordPress site url and home when using search replace to mitigate object cache issue on cloning. Copy button added to domains table. Improved Hebrew and Portugese translations. Increased timeout for email role migration again. Primary domain now always listed first on domains table. wp-admin button on the website dashboard now defaults to the installation in public_html ahead of any addon domains. Fixed Application installations now adhere to package database resource limits.

View originalPermalink

12.22.2AI extracted

It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Fixed Resolved error when creating PostgreSQL databases under a website beginning with a number. Enhanced Increased timeout for WHM API client to 1 hour to improve cPanel import from remote server when dealing with very large accounts. Improved error messages for website cloning and push-live. Improved cleanup of mysql.db table when a MySQL database is removed. Panel lists now use brand accent colour. Spacing issue on catch-all checkbox.

View originalPermalink

12.22.1AI extracted

It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Fixed PostgreSQL resource count now shows correctly in package resource listing where the resource was set to 0 during initial package creation. Mitigation for rsync "link dest" regression in 3.2.7-1ubuntu1.4 package. Backup restoration no longer returns a false failure notice when no PostgreSQL server is available. Enhanced Increased RPC timeout for application role transfer.

View originalPermalink

12.22.0AI extracted

It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Documentation here Added It is now possible to optionally install the PostgreSQL role to servers within your cluster and to provide PostgreSQL hosting to your customers. pgsql and pdo_pgsql PHP modules are enabled automatically if a PostgreSQL database is created by the customer. Enhanced Increased email transfer RPC timeout. Additional prompt for resellers to set a control panel domain when creating a customer, if no control panel domain has been set. phpMyAdmin button added to database listing. In the file manager, document roots are now highlighted by a 'globe' icon. Connection guidance added to database management page for end users. MariaDB LTS initial installation now explicitly sets utf8mb4 server character set in my.cnf. Efficiency and performance improvements to internal APIs. dump.rdb (Redis persistent data store) now automaticallyt excluded from website cloning. Improvements to backup transfer guard logic when attempting new website backups. Roundcube version bumped to 1.6.16. Removing all database privileges for a user means the user is no longer listed under the database. Improved error messages for remote MySQL connection failure. Added database size to backup listing. Container IP now automatically allowed for new MySQL users where the application and database roles are on the same server. Plesk importer now handles backups with missing 'directories' param. MySQL databases now listed on the package subscription card where the resource is set to unlimited. Fixed Removed onclick and 'manage' dropdown option for preview aliases which cannot be managed. UI for resellers no longer attempts to set deprecated 'processes' resource. WordPress username update via WordPress toolkit now functional. Corrected chowning logic for Litespeed (commercial) virtual host config files. SMTP SASL auth now correctly disabled when configuring a smart host with no credentials.

View originalPermalink

12.21.6AI extracted

Hide 'mailq' and 'postqueue' binaries from customer container. Improved cleanup of expired "run in customer container" tasks initiated by WordPress/Joomla toolkit to prevent potential task queue overrun.

View originalPermalink

12.21.5AI extracted

Due to the recent local privilege escalation (LPE) vulnerabilities in the Linux kernel targetting setuid binaries (CVE-2026-43284, CVE-2026-43500, CVE-2026-31431, etc), this release now hides known setuid binaries from website containers. This does not make your system immune to such vulnerabilities but it does limit potential attack vectors and would frustrate any attacks originating from a compromised CMS or a malicious customer. This provides no protection from attacks originating from a non-Enhance user or from a remote code execution (RCE) in software which does not run within an Enhance website container. This does not negate the need to keep your system up to date or to apply any temporary mitigations to current or future LPE vulnerabilities. To benefit from this change, you must reboot the system after installing the updated Enhance packages.

View originalPermalink

12.21.4AI extracted

Failure to update backup destination on application/email server when migrating a website which previously had no backup server set to a new backup server.

View originalPermalink

12.21.3AI extracted

Removed ability of collaborator role to add/delete Cloudflare tokens via API. End user must supply subscription ID when cloning to a new website via API.

View originalPermalink

12.21.2AI extracted

All global backup settings are now re-applied on installation of a new Backup role. Improved handling of expired snapshot deletion where directories are missing read or execute permissions. Expired snapshot cleanup runs less frequently and on a separate scheduler. File manager can now handle directories which are unreadable due to file permissions.

View originalPermalink

12.21.1AI extracted

Increased Let's Encrypt initial connection timeout. Improvements to Polish language pack. Altered RPC keepalive strategy for transfer of backup data between servers. "Built in" PHP extensions displayed in website dashboard now include compulsory extensions loaded at runtime in addition to those compiled in to PHP. Unix username generation for numeric domains of more than 8 characters in length.

View originalPermalink

12.21.0AI extracted

The PHP extension manager under 'Developer tools' > 'PHP' now allows customers to enable any extension that you have built/installed within the global extension directory for their chosen version of PHP, in place of the predefined list. For guidance on how to add additional configurable extensions click here. The "developer tools" section of the website dashboard now lists built-in PHP extensions in addition to optional extensions. Enabled PHP extensions now persist after server migration. When changing PHP version, any incompatible extensions are now disabled automatically. On Apache and Nginx web server kinds, mod_security is explicitly disabled for the per-server Roundcube installation ( https://mail.customerdomain). Control panel websites can no longer be mapped to a database server. New backups are no longer started during a backup migration to improve transfer performance. Cleanup of expired snapshots is no longer performed during a backup migration to improve transfer performance. Website backup destination is now performed after a successful traansfer of the backup role. Improvements to the effiency/speed of expired snapshot cleanup. MySQL 8.4 is now the default version when MySQL is selected due to 8.0 EOL. Prevent excessive logging where the per-server Roundcube website has not yet been created.

View originalPermalink

12.20.1AI extracted

An optional description has been added to token creation from CLI. Supported Roundcube version has been updated to 1.6.15. File manager proxy configuration is automatically regenerated when a server's primary IPv4 address is updated in the Enhance user admin interface.

View originalPermalink

12.20.0AI extracted

Per-server Roundcube (responsible for https://mail.domain) now auto-updates to the latest supported Roundcube version, currently 1.6.14. Minor UI rendering issues during role installation.

View originalPermalink

12.19.0AI extracted

Default PHP version for Central Roundcube and phpMyAdmin is now 8.3. Service websites can have their PHP version changed with the bulk update tool. Onboarding help card can now be permanently dismissed across all devices. Please hard refresh in your browser prior to dismissing the banner. Joomla installation now allows 10 character passwords. Swap limit (system resource) can now be set to 0.

View originalPermalink

12.18.0AI extracted

Joomla one click installer. If 'Allow software installer' is enabled on a package, Joomla will automatically be available to the user. Default PHP version for new websites and packages is now 8.3. Underscores are now valid is NS names.

View originalPermalink

12.17.0AI extracted

It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Roundcube SSO support. This requires SSO to be enabled on a per-server basis. Documentation can be found here. Improved Vietnamese language pack File manager no longer allows quota bypass Overriding website memory limit to unlimited is now applied immediately Option to overwrite conflicting files when unzipping with the file manager Fixed typo on Plesk importer

View originalPermalink

12.16.1AI extracted

Dovecot reload after adding a domain is now debounced to prevent excessive reloading when a large amount of domains are added in a short period of time.

View originalPermalink

12.16.0AI extracted

The ability to clone to staging from the website dashboard hero section Database sizes now show in database listing Website size now includes home directory, databases and emails Subscription disk usage now properly counts database and email usage Clone to staging can no longer bypass staging website limit Global smart host is now applied to standalone control panel servers on save

View originalPermalink

12.15.1AI extracted

Impersonation now persists when a hard refresh is performed in the browser. Swap limit now displays correctly on packages created on versions < 12.15.0.

View originalPermalink

12.15.0AI extracted

It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. The ability to restore individual files from an Enhance website backup. S3 backups are now tagged with 'S3' (this is visible to the end user). This is essential to highlight as S3 backups do not allow granular file restores. Ability to limit swap usage under "system resource limits". Packages created before the upgrade to 12.15.0 may show the swap limit as being 0 but this will remain at the previous setting (unlimited) until the package is updated. Database restore can now handle databases which have been dropped from the command line. IMAP module enabled by default on PHP 8.4 and 8.5 (new and existing websites). imagick module enabled by default on PHP 8.5 (new and existing websites).

View originalPermalink

12.14.3AI extracted

Corrected subscription bandwidth calculation. Subscription recalculation is now forced after successful website clone. Cloning process only checks for database resource on the destination package where databases exist on the source website. Improved fault tolerance for automated o/s package installation (apt).

View originalPermalink

12.14.2AI extracted

Race condition causing a node.js application, when automatically started via Enhance, not to be placed into the correct control group. Removed duplicate API call for memory usage on server management dashboard. /usr/bin/composer is now checked for validity on installation of ecp-core and, if not valid, composer is re-downloaded. Miscellaneous UI improvements. Stricter RPC timeouts to DNS sync queue to prevent slow queue processing where some DNS servers in the cluster are offline.

View originalPermalink

12.14.1AI extracted

Incorrect CPU core count on virtual machines where cores are presented by the hypervisor to the guest as separate physical CPUs. Application role installation now explicitly installs the mariadb-client package if the database role is not installed. Database role transfer now checks mysql client version for appropriate command line arguments when the transfer is initiated by a standalone app server with no database role installed. Improved Polish language pack.

View originalPermalink

12.14.0AI extracted

Server specifications now shown in master organisation "servers" dashboard. Customers with dedicated subscriptions can now view server specifications, load, memory and swap usage. Traditional Chinese (Taiwan) locale (Beta). Editing IP in "connectivity check" modal no longer resets the IP when the existing IP is totally removed. It is now possible to access decommission/delete options for an offline server. Backup settings are now explicitly re-applied to servers on role installation/reinstallation. Migration of application role to a server where the email role is already placed now explicitly applies the local/remote setting per domain from the control panel database. WordPress SSO plugin is now downloaded and cached at a server level for faster activation and avoidance of Github API rate limits. Reduced API calls from /servers page for better performance. Improved performance and reduced memory usage of website DNS resolution check.

View originalPermalink

12.13.3AI extracted

Default Roundcube version is now 1.6.12.

View originalPermalink

12.13.2AI extracted

Connectivity diagnosis for servers which are unreachable from the control panel server. Additional error logging for S3 errors. On OpenLiteSpeed install, "systemctl daemon-reload" is retried multiple times. Fix for a cPanel import where home dir on the cPanel side is non-standard.

View originalPermalink

12.13.1AI extracted

When the root of a domain is proxied to a Node.js app, .well-known/acme-challenge is explicitly excluded from the proxy on all web server kinds.

View originalPermalink

12.13.0AI extracted

Users on the per-server Roundcube (https://mail.customer-domain) can now change their password in the Roundcube UI. To enable this functionality on existing installations, run "ecp install-round-cube-password-plugin" as root on each mail server. PHP 8.5 support. Currently Ioncube and PECL imagick modules are not supported on PHP 8.5, pending release of new versions by these providers. To provide PHP 8.5 to customers, please ensure that 'PHP 8.5' is enabled on their hosting package. On installation of the application or email role on a server, the S3 credentials (if present) are automatically synchronised to that server. Supporting UI to pre-install a custom WordPress plugins from a URL. When a container is restarted, the previous virtual interface device is now explicitly taken down incase another process is holding open the network namespace. Improved Polish language pack. Improved Turkish language pack. Improved Spanish language pack. Global webmail has been positioned as the secondary option under the 'advanced' dropdown

View originalPermalink

12.12.0AI extracted

DS/CAA records can now be added to DNS zones and DNS templates. Default TTL setting can now be set under Platform Settings. The default TTL is 1400 sec and will only apply to new websites. When creating a new record if a TTL is not specified, it now mirrors the SOA TTL. Where the web server is OpenLitespeed/Litespeed, it is now possible to limit LSAPI_CHILDREN via the website overrides panel. It is now possible to disable backups on a website via the website overrides panel. A WordPress username can be an email. Improved NL language pack. Improved Turkish language pack. PHP FPM settings now hidden from website overrides panel when the web server is Litespeed/OpenLitespeed. Mariadb installation now uses alternative apt repository. Increased timeouts for Let's Encrypt provisioning (automatic and manual).

View originalPermalink

12.11.10AI extracted

Warnings in UI when I/O and IOPS limits are set too low on package level and per-website override. Hanken Grotesk Google font. MariaDB repo config no longer uses mariadb install script. Ghost button consistency. IOPS limit calculations. IO bandwidth was applied in the wrong order of magnitude (gigabytes instead of megabytes). Warning: if you had set very low IO limits previously and these were not being enforced, they will be enforced on the next container update. Check your package settings are sensible. Increased timeout for manual Let's Encrypt issuance Turkish language pack improvements. Logs page redesign.

View originalPermalink

12.11.9AI extracted

Updated mysql.com trusted GPG key.

View originalPermalink

12.11.8AI extracted

Double search/replace on WordPress site URL during cloning or push-live when "perform search and replace" is selected. Reduced memory usage of appcd service during backup runs. System MTA is explicitly installed and configured during control panel initialisation. Failure to update WordPress site URL during website cloning is now non-fatal.

View originalPermalink

12.11.7AI extracted

A reseller can no longer create customers via the API without the "resellerSubResellers" allowance on their own package. German translation improvements. The list of endpoints accessible to a login session which has not yet completed 2 factor authentication has been further restricted.

View originalPermalink

12.11.6AI extracted

libsasl2-modules package is now specifically installed alongside Postfix MTA. Support user can no longer change screenshot settings. Master organisation collaborator can no longer view activity log. Reinstated missing context menu on database user listing with table row height fix. Tighter rate limiting for 2FA.

View originalPermalink

12.11.5AI extracted

White page bug in UI when managing control panel websites. External application names in Openlitespeed web server are now unique when using Node.js. Improved validation of collaborator access level.

View originalPermalink

12.11.4AI extracted

App role migration reinstates Node.js deployments. Prevent system actions by Support user. Deleting an addon domain now also removes the DNS zone. API no longer allows % in email username. Cleanup of created databases and database users if failure occurs during the creation phase. "Download email data" no longer shows on dashboard where no email server exists. Improved Ukrainian language pack. Improved 'tag' functionality on subscriptions. Inline logs and general UI improvements to 'PHP' section.

View originalPermalink

12.11.2AI extracted

Invited master organisation support and business users can no longer update the licence key. appinit now sets PHPRC environment variable when starting lsphp to prevent loading of custom php.ini from the home dir where it has been imported from another panel.

View originalPermalink

12.11.3AI extracted

UI bug when packages are created by a reseller where the reseller's own package does not support Node.js.

View originalPermalink

12.11.1AI extracted

This update contains a security patch related to user role permission handling in the control panel API. We recommend applying it as soon as possible.

View originalPermalink

12.11.0AI extracted

IMPORTANT: Prior to this version, "force https" if enabled on your control panel domain would not redirect requests for paths beginning with /api when running Apache on your control panel web server. This behaviour has been corrected and requests to /api now obey the "force https" setting. If /api is accessed on port 80, a 301 response will be sent. Node.js support. See documentation Performance improvements to how containers are started. Improvements to simplified Chinese language pack. Improved Portuguese language pack.

View originalPermalink

12.10.6AI extracted

Additional validation of mysql database names. Reduced concurrency for deletion of expired backup snapshots to reduce load on backup servers with limited i/o.

View originalPermalink

12.10.5AI extracted

Further improvements to validation of pre-hashed mailbox passwords.

View originalPermalink

12.10.4AI extracted

Improved validation of pre-hashed mailbox passwords to prevent potential breakage of dovecot user db.

View originalPermalink

12.10.3AI extracted

Improved image handling and detection for SVG images in branding settings. Added additional Content-Type header for auto reply messages to fix Roundcube display issue.

View originalPermalink

12.10.0AI extracted

Ability to download/upload an Enhance website backup. See documentation Azerbaijani language pack (beta). Improved Norwegian language pack. Fixed intermittent bug with maildir user creation group ownership. Pre-existing mailbox directory is no longer a fatal error if owned by the website user. Removed upload limit for file uploads to the Enhance panel.

View originalPermalink

12.10.1AI extracted

Downloadable backups skip unreadable files. Document root permissions are now checked/reset after backup upload. Home dir data no longer copied when downloading email-only backup where the app + email roles are placed on the same server.

View originalPermalink

12.10.2AI extracted

UI white screen bug when managing control panel and central webmail websites. Clear your browser cache after applying this update.

View originalPermalink

12.9.9AI extracted

On installation, Enhance now installs the latest version of LiteSpeed (v6.3.4). Only run the below command if you are using commercial Litespeed Existing Enhance users running LiteSpeed can update to Litespeed v6.3.4 by running the following command on each server running LiteSpeed; mv /usr/local/lsws /usr/local/lsws_old && appcd-cli change-webserver lite-speed put-your-serial-no-here

View originalPermalink

12.9.8AI extracted

A users 2FA status is now displayed on the 'Users' page. It is now possible to delete a preview domain. See documentation S3 backup is now tolerant of missing mail directories. Moving an application role away from a server whilst leaving the email role behind now removes the user crontab from the source server.

View originalPermalink

12.9.7AI extracted

Improved startup time of appcd for servers with a high website count (5000+). Increased RPC timeout for post migration success cleanup. A reseller can be downgraded to a non-reseller package if they have previously created and deleted customers. A reseller can set an upper limit on dynamic mailbox size if their own subscription is unlimited.

View originalPermalink

12.9.6AI extracted

appcd process monitor no longer waits for pids it has not explicitly killed. Prevention of "double slash" in nginx SCRIPT_FILENAME env var passed to PHP

View originalPermalink

12.9.5AI extracted

Updating preinstalled theme on an existing package had no effect.

View originalPermalink

12.9.4AI extracted

appinit will clean up orphaned processes that it becomes the owner of due to the original parent process ending. Cloudflare integration now explicitly sends quotation marks around TXT record. Onboarding of new servers to an existing cluster will ignore any ipv6 records in DNS. Additional guidance in ecp join error output. It was not possible to remove a domain mapping from a website if another domain existed which ended in the domain to be deleted.

View originalPermalink

12.9.3AI extracted

It is now possible to limit the number of DNS records that can be created per domain on a package level. Increased timeouts for wp-cli, composer and ioncube loader install during ecp-core package postinst script.

View originalPermalink

12.9.2AI extracted

Custom backup restore not possible on S3. Database failure to restore when restoring S3 full website backup.

View originalPermalink

12.9.0AI extracted

By default PHP SAPI starts on demand to reduce memory usage from idle websites, whilst maintaining containerisation. Idle websites now use approximately 2mb of RAM not 60mb. Each server within a cluster now displays the Enhance version it's running. Staging domains are now 'noindex' by default to newly added websites. Improvements to Hebrew language pack. php-error.log no longer backs up. Session cookie sends SameSite=none when custom CORS is enabled. Fix for cron jobs being overwritten when added via the UI if the crontab contained blank lines, comments or environment variables. Fix for logging of false backup error where no primary domain mapping existed on the Application server. Fix for cron issue where blank lines or environment variables in the user's crontab could cause cron jobs to be overwritten when edited from the UI. Fix for process manager interrogation of existing processes.

View originalPermalink

12.9.1AI extracted

UI bug when editing empty user cron tab.

View originalPermalink

12.8.0AI extracted

Catch-all email addressses. Documentation can be found here. Access token IP lockdown. Ability to edit roles for existing access tokens. Access token management added to ecp CLI tool. 'Host' and 'Port' prompts added to the FTP Login credential card.

View originalPermalink

12.7.1AI extracted

UI rendering error on customer management page, email tab. Excessive truncation of file size on website backup card. Email role transfer RPC timeout increased to 1 day.

View originalPermalink

12.7.0AI extracted

It is now possible for the master organisation to restore backups of websites which were permanently deleted if they were backed up using the Enhance backup role. Note, it may not always be possible to restore backups created prior to version 12.7.0. Documentation can be found here. Improvements to website restore logic for customers using the Enhance backup role. Improvements to disaster recovery logic for customers using the Enhance backup role. Email and mailbox logic moved to the application server (appcd) in preparation for future "portable backup" and CLI restore functionality. Improvements to Norwegian language pack. Improvements to Polish language pack. Backups using the Enhance backup role now contain DNS data. WordPress toolkit can now handle deprecated warnings injected inline from plugins such as Elementor. Improved error messages for RPC connectivity. Group ID bug in file manager (filerd) service.

View originalPermalink

12.6.2AI extracted

Default Roundcube version for per-server installation is now 1.6.11.

View originalPermalink

12.6.1AI extracted

Automatic and manual backups will now retry the rsync operation if it fails on the first attempt. Backup process can now recover if the home directory for the backup user is manually deleted. Backup process is now less sensitive to hard disk quota issues on the source server. Upgrade from v11 now explicitly sets www-data group ownership on public_html even if it does not match the document root of a mapped domain. "No S3 settings" is now logged to the trace log rather than the error log to avoid excessive log noise. MariaDB repo download script now forces ipv4 to mitigate an issue with some ipv6 IPs being blocked by MariaDB. Improvements to wp-cli cache warmer utility. Mitigation for issue where email and website backup run on separate servers at the exact same time. Bandwidth counter (total) rounding error. Resource calculation endpoint now saves the result to the database. Moving a standalone database role from a decommissioned server did not update the remote SQL settings on the target application server.

View originalPermalink

12.6.0AI extracted

Reinstated backup failure logging to the activity log for customers on version 12.x. Moved logic for management of local .my.cnf file to appcd service for improved performance. Local .my.cnf is now checked and repaired before each backup or restore operation. Attempting to create a central webmail website with no database role installed now generates a descriptive error. Added mitigation for incompatible collations when cloning a website from a server with MariaDB to a server with MySQL. SuperAdmin can now set admin lockdown via API to allow for automation with bearer token. /var/lib/mysql and /var/lib/docker now totally hidden from website containers. Race condition where the local .my.cnf had been modified and website files were restored before databases which prevented a restore of the database. Descriptive text for email rate limits was incorrect in English language. System commands in platform update instructions excluded from translation. Issue backing up databases with massive text rows on some versions of MariaDB.

View originalPermalink

12.5.1AI extracted

Using SSO when a previously expired session existed would require a hard refresh. Additional guidance on licence settings page where licence status is Unknown.

View originalPermalink

12.5.0AI extracted

Ability to restrict access to the Master Organisation (interactive login and SSO) by IP address. This does not affect access tokens. Click here for documentation. Incorrect domain sort order on email creation for users of Chrome browser. Auto generated invite link was missing :2087 for clusters without a control panel domain configured. Prohibited domain UI was incorrectly shown to resellers. pt-PT language pack improvements. With thanks to João Costa – WebDig Host. Plesk importer can now handle generated XML with self-closing tags, created by some versions of Plesk.

View originalPermalink

12.4.0AI extracted

Setting to enable "email server stickiness", to default the Email role for a website to be placed or the same server as the Application role if the Email role is installed. Customer and subscription stickiness were incorrectly applied when toggled in the UI. Improved guidance for setting of HELO name.

View originalPermalink

12.3.3AI extracted

Redis status persisted on website migration. Ioncube status persisted on website migration. Package setting for automatic installation of WooCommerce now working. WP plugin list tolerates boolean "update" parameter in json plugin listing from wp-cli. File manager text editor now functional in RTL locales. Primary domain now appear at the top of the domain selector when creating a new email address. In file manager, files with non-utf8 encoded filenames no longer cause a fatal error, instead any invalid characters are displayed as �. appcd-cli list-websites now returns JSON output. Hebrew language improvements. A more informative error is given when a reseller or master organisation has no phpMyAdmin domain configured. Custom CORS feature now permits multiple origins. Openlitespeed is now explicitly restarted after installation to pick up Enhance systemd override drop-in. Openlitespeed is now explicitly uninstalled when changing to another web server type. WordPress auto discovery tolerates longer database names from imported websites. Added port 587 to email client config guidance.

View originalPermalink

12.3.2AI extracted

French language pack improvements. orchd service will now wait for initialisation of master organisation before starting internal workers. Intermittent issue with restoring large database tables when using S3-compatible backup system. Failure to remove expired snapshots when using S3-compatible backup system.

View originalPermalink

12.3.1AI extracted

Improvements to licence check logic in orchd service. Website backup restore now matches previous behaviour from versions < 12.0.0; files which exist on the website but which do not exist in the chosen restore point are removed. Improved pt-BR locale.

View originalPermalink

12.3.0AI extracted

The createWebsite endpoint will now install WordPress and any preinstalled plugins and themes if specified on the customer's hosting package. This removes the need for separate API calls. Important if you have an external integration, please verify compatibility before upgrading Enhance to this version. Improved Norwegian language pack. Improved Arabic language pack. Thank you to WebGee Ltd ( https://webgee.com). Improved Ukranian language pack. New override for apache2 systemd unit to mitigate problem with large file uploads when mod_security is enabled. Internal filerd token timeout during large website clones.

View originalPermalink

12.2.0AI extracted

Hebrew language pack (kindly provided by Devim Cloud) Support for legacy PHP 5.2 - 5.5. Running PHP 5.2, PHP 5.3, PHP 5.4 and PHP 5.5 is optional. To provide these PHP version you will need to manually install the packages on your platform. Follow this guide. Improved Portugese and Bulgarian language pack. Added Restart=always to lshttpd systemd override. Fix for missing /dev/tty device in customer SSH environment. CHMOD setting now applies recursively.

View originalPermalink

12.1.0AI extracted

Support for sending custom access-Host-Allowed-Origin header from control panel API. Backup process is now tolerant of the previous snapshot having been manually removed. WordPress plugin installation API can now accept a URL for installation of plugins not registered with WordPress.org.

View originalPermalink

12.0.28AI extracted

Improved logic for error handling in backups to the Enhance backup target.

View originalPermalink

12.0.29AI extracted

Automatic rebuild of resolv.conf within postfix chroot.

View originalPermalink

12.0.30AI extracted

Improved logic for de-duplication of backup data during role migration.

View originalPermalink

12.0.27AI extracted

Backup destination was not updated on the destination server during application role transfer. ecp sso now prints an SSO link for the control panel domain in addition to the IP. Increased timeout for post migration cleanup activities.

View originalPermalink

12.0.26AI extracted

appcd-cli utility can optionally specify the website kind.

View originalPermalink