# Enhance changelog > Clustered web hosting control panel with website, server and reseller management. - Vendor: Enhance Hosting Automation - Category: Developer Tools - Official site: https://enhance.com - Tracked by: What's New (https://whatsnew.fyi/product/enhance) - Harvested from: AI extracted - Entries below: 25 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. ## Releases ### 12.25.4 — 12.25.4 Latest - Date: 2026-08-03 - Version: 12.25.4 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.25.4 - **changed** — cPanel importer now tolerates numeric values for 'ssl' and 'port' in cPanel userdata domain files to mitigate recent changes in cPanel - **changed** — WordPress installation via wp-cli now prefers the zip archive to mitigate an issue with extraction of long path names from tar files in the current version of wp-cli - **fixed** — When a customer package defines preinstalled WordPress plugins, a false error message is no longer displayed when Openclaw is installed Enhanced cPanel importer now tolerates numeric values for 'ssl' and 'port' in cPanel userdata domain files, to mitigate recent changes in cPanel. WordPress installation via wp-cli now prefers the zip archive to mitigate an issue in with extraction of long path names from tar files in the current version of wp-cli. Fixed When a customer package defines preinstalled WordPress plugins, a false error message is no longer displayed when Openclaw is installed. ### 12.25.3 - Date: 2026-08-01 - Version: 12.25.3 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.25.3 - **security** — SVG uploads from resellers and end users are now explicitly checked for Javascript content which might be executed if the SVG file were opened directly in the browser - **fixed** — Customer stickiness now ignores service websites belonging to that customer when determining placement of a new website Security SVG uploads from resellers and end users are now eplicitly checked for Javascript content which might be executed if the SVG file were opened directly in the browser. Fixed Customer 'stickiness', if enabled, now ignores service websites belonging to that customer when determining placement of a new website. ### 12.25.2 - Date: 2026-07-30 - Version: 12.25.2 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.25.2 - **changed** — Dev dependencies are now removed before running the composer install command when installing the wp-cli login package as part of the ecp-core postinst script Enhanced When installing the wp-cli login package as part of the ecp-core postinst script, dev dependencies are removed before running the composer install command. ### 12.25.1 - Date: 2026-07-23 - Version: 12.25.1 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.25.1 - **fixed** — cPanel imports now complete where PostgreSQL is enabled on cPanel but not on Enhance by skipping any PostgreSQL databases during the import process - **changed** — Search login on Customers has been moved from UI code to API to improve performance on larger clusters - **changed** — Improved phpMyAdmin error reporting - **changed** — Overrides back heading now contains the primary domain of the website being edited - **changed** — getGlobalInstallableApps and getInstallableApps endpoints now return OpenClaw as a supported application - **fixed** — phpMyAdmin domain selection for resellers now ignores soft-deleted domains - **fixed** — API will no longer accept syntactically invalid ".." in email local part Enhanced cPanel imports are now able to complete where PostgreSQL is enabled on cPanel but not on Enhance, by skipping any PostgreSQL databases during the import process. The search login on 'Customers' has been moved from UI code to API to improve performance on larger clusters. Improved phpMyAdmin error reporting. "Overrides" back heading now contains the primary domain of the website being edited. getGlobalInstallableApps and getInstallableApps endpoints now return OpenClaw as a supported application. getInstallableApps returns applications subject to package restrictions. Fixed phpMyAdmin domain selection for resellers now ignores soft-deleted domains. API will no longer accept syntactically invalid ".." in email local part. ### 12.25.0 - Date: 2026-07-20 - Version: 12.25.0 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.25.0 - **added** — 3rd party DNS hooks added to Integrations - **added** — Default DMARC policy set to p=none for all new zones, editable per website or as platform DNS zone template - **added** — installServerRole API endpoint has an additional parameter to disable the role on installation - **added** — Disabled server roles are automatically enabled when a customer is subscribed to a dedicated plan using that server/role - **added** — New getPhpMyAdminWebsiteSSOUrl endpoint added which does not require a specific database name - **changed** — Improved Danish translations - **changed** — New Quick Links section added for website dashboard - **changed** — Reseller subscription recalculation is now triggered after a soft deletion of a customer org - **changed** — orchd, appcd and appd now only start if started by systemd to prevent overzealous LLMs starting duplicate copies - **changed** — orchd will no longer start as root - **changed** — Improved email transfer logic and failure handling - **fixed** — Push live now copies cron jobs - **fixed** — Push live now copies IonCube - **fixed** — Reseller control panel domain warning Added 3rd party DNS hooks added to 'Integrations'. Default DMARC added for all new zones. The default policy is set to 'p=none', this can be edited on a per website in Website > Domain > DNS records or as a platform DNS zone template in Settings > Platform > DNS. installServerRole API endpoint has an additional parameter to disable the role on installation. Disabled server roles are automatically enabled when a customer is subscribed to a dedicated plan using that server/role. Enhanced New getPhpMyAdminWebsiteSSOUrl endpoint added which does not require a specific database name (existing getPhpMyAdminSSOUrl endpoint is still functional) Improved Danish translations. New 'Quick Links' section for website dashboard. A reseller subscription recalculation is now triggered after a soft deletion of a customer org. orchd, appcd and appd now only start if started by systemd, to prevent overzealous LLMs starting duplicate copies of appcd. orchd will no longer start as root. Improved email transfer logic and failure handling Fixed "Push live" now copies cron jobs. "Push live" now copies IonCube. Reseller control panel domain warning. ### 12.24.0 - Date: 2026-07-03 - Version: 12.24.0 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.24.0 - **added** — Enable the ability to edit cron jobs with SSH or any other process running under the website container via the developer tools section of the website dashboard - **added** — OpenClaw is now available as an installable application via the apps tab of the website dashboard - **added** — OpenClaw toolkit can add API provider keys, rotate tokens and configure device authentication - **added** — Packages can now be configured to restrict the installable applications - **changed** — Numeric progress indicator added to file manager upload - **fixed** — Additional improvements to UI domain sorting login on domains tab of website dashboard Added Customers can now enable the ability to edit cron jobs with SSH (or any other process running under the website container) via the "developer tools" section of the website dashboard. OpenClaw is now available as an installable application via the "apps" tab of the website dashboard. OpenClaw toolkit can add API provider keys, rotate tokens and configure device authentication. Packages can now be configured to restrict the installable applications. Enhanced Numeric progress indicator added to file manager upload. Minor UI improvements. Fixed Additional improvements to UI domain sorting login on "domains" tab of website dashboard. ### 12.23.1 - Date: 2026-06-22 - Version: 12.23.1 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.23.1 - **fixed** — 401 error no longer returned when attempting to "log out all devices" from user profile - **fixed** — Primary domain now correctly shows at the top of page 1 when listing website mapped domains spanning multiple pages Fixed 401 error no longer returned when attempting to "log out all devices" from user profile. Primary domain now correctly shows at the top of page 1 when listing website mapped domains spanning multiple pages. ### 12.23.0 - Date: 2026-06-15 - Version: 12.23.0 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.23.0 - **added** — Node.js websocket proxy support - **added** — Inode resource limit per website as a package setting that can be overridden on a per website basis - **changed** — PostGIS and PGVector now enabled by default on new PostgreSQL installations - **changed** — Automatically recalculate subscription on cloning failure - **changed** — Default post_max_size and upload_max_filesize now 1000M if no specific limit is configured - **changed** — Explicitly set WordPress site url and home when using search replace to mitigate object cache issue on cloning - **changed** — Copy button added to domains table - **changed** — Improved Hebrew and Portugese translations - **changed** — Increased timeout for email role migration - **changed** — Primary domain now always listed first on domains table - **changed** — wp-admin button on the website dashboard now defaults to the installation in public_html ahead of any addon domains - **fixed** — Application installations now adhere to package database resource limits It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Added Node.js websocket proxy support. Inode resource limit per website. This is a package setting and can be overriden on a per website basis. Documentation can be found here. Enhanced PostGIS and PGVector now enabled by default on new PostgreSQL installations. Automatically recalculate subscription on cloning failure. Default post_max_size and upload_max_filesize now 1000M if no specific limit is configured. Explicitly set WordPress site url and home when using search replace to mitigate object cache issue on cloning. Copy button added to domains table. Improved Hebrew and Portugese translations. Increased timeout for email role migration again. Primary domain now always listed first on domains table. wp-admin button on the website dashboard now defaults to the installation in public_html ahead of any addon domains. Fixed Application installations now adhere to package database resource limits. ### 12.22.2 - Date: 2026-06-01 - Version: 12.22.2 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.22.2 - **fixed** — Resolved error when creating PostgreSQL databases under a website beginning with a number - **changed** — Increased timeout for WHM API client to 1 hour to improve cPanel import from remote server when dealing with very large accounts - **changed** — Improved error messages for website cloning and push-live - **changed** — Improved cleanup of mysql.db table when a MySQL database is removed - **changed** — Panel lists now use brand accent colour - **fixed** — Fixed spacing issue on catch-all checkbox It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Fixed Resolved error when creating PostgreSQL databases under a website beginning with a number. Enhanced Increased timeout for WHM API client to 1 hour to improve cPanel import from remote server when dealing with very large accounts. Improved error messages for website cloning and push-live. Improved cleanup of mysql.db table when a MySQL database is removed. Panel lists now use brand accent colour. Spacing issue on catch-all checkbox. ### 12.22.1 - Date: 2026-05-28 - Version: 12.22.1 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.22.1 - **fixed** — PostgreSQL resource count now shows correctly in package resource listing where the resource was set to 0 during initial package creation - **fixed** — Mitigation for rsync "link dest" regression in 3.2.7-1ubuntu1.4 package - **fixed** — Backup restoration no longer returns a false failure notice when no PostgreSQL server is available - **changed** — Increased RPC timeout for application role transfer It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Fixed PostgreSQL resource count now shows correctly in package resource listing where the resource was set to 0 during initial package creation. Mitigation for rsync "link dest" regression in 3.2.7-1ubuntu1.4 package. Backup restoration no longer returns a false failure notice when no PostgreSQL server is available. Enhanced Increased RPC timeout for application role transfer. ### 12.22.0 - Date: 2026-05-26 - Version: 12.22.0 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.22.0 - **added** — Optionally install the PostgreSQL role to servers within your cluster and provide PostgreSQL hosting to your customers - **added** — pgsql and pdo_pgsql PHP modules are enabled automatically if a PostgreSQL database is created by the customer - **changed** — Increased email transfer RPC timeout - **changed** — Additional prompt for resellers to set a control panel domain when creating a customer, if no control panel domain has been set - **changed** — phpMyAdmin button added to database listing - **changed** — In the file manager, document roots are now highlighted by a 'globe' icon - **changed** — Connection guidance added to database management page for end users - **changed** — MariaDB LTS initial installation now explicitly sets utf8mb4 server character set in my.cnf - **changed** — Efficiency and performance improvements to internal APIs - **changed** — dump.rdb (Redis persistent data store) now automatically excluded from website cloning - **changed** — Improvements to backup transfer guard logic when attempting new website backups - **changed** — Roundcube version bumped to 1.6.16 - **changed** — Removing all database privileges for a user means the user is no longer listed under the database - **changed** — Improved error messages for remote MySQL connection failure - **changed** — Added database size to backup listing - **changed** — Container IP now automatically allowed for new MySQL users where the application and database roles are on the same server - **changed** — Plesk importer now handles backups with missing 'directories' param - **changed** — MySQL databases now listed on the package subscription card where the resource is set to unlimited - **fixed** — Removed onclick and 'manage' dropdown option for preview aliases which cannot be managed - **fixed** — UI for resellers no longer attempts to set deprecated 'processes' resource - **fixed** — WordPress username update via WordPress toolkit now functional - **fixed** — Corrected chowning logic for Litespeed (commercial) virtual host config files - **fixed** — SMTP SASL auth now correctly disabled when configuring a smart host with no credentials It is very important for this release that all servers are updated to the same version to avoid undefined behaviour. As root on each server in your cluster run 'apt update && apt upgrade'. Documentation here Added It is now possible to optionally install the PostgreSQL role to servers within your cluster and to provide PostgreSQL hosting to your customers. pgsql and pdo_pgsql PHP modules are enabled automatically if a PostgreSQL database is created by the customer. Enhanced Increased email transfer RPC timeout. Additional prompt for resellers to set a control panel domain when creating a customer, if no control panel domain has been set. phpMyAdmin button added to database listing. In the file manager, document roots are now highlighted by a 'globe' icon. Connection guidance added to database management page for end users. MariaDB LTS initial installation now explicitly sets utf8mb4 server character set in my.cnf. Efficiency and performance improvements to internal APIs. dump.rdb (Redis persistent data store) now automaticallyt excluded from website cloning. Improvements to backup transfer guard logic when attempting new website backups. Roundcube version bumped to 1.6.16. Removing all database privileges for a user means the user is no longer listed under the database. Improved error messages for remote MySQL connection failure. Added database size to backup listing. Container IP now automatically allowed for new MySQL users where the application and database roles are on the same server. Plesk importer now handles backups with missing 'directories' param. MySQL databases now listed on the package subscription card where the resource is set to unlimited. Fixed Removed onclick and 'manage' dropdown option for preview aliases which cannot be managed. UI for resellers no longer attempts to set deprecated 'processes' resource. WordPress username update via WordPress toolkit now functional. Corrected chowning logic for Litespeed (commercial) virtual host config files. SMTP SASL auth now correctly disabled when configuring a smart host with no credentials. ### 1.30.2 — Nginx 1.30.2 - Date: 2026-05-23 - Version: 1.30.2 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/1.30.2 - **security** — Addresses CVE-2026-9256 New nginx stable package. Run apt update && apt upgrade to update. Addresses CVE-2026-9256. ### 1.30.1 — Nginx 1.30.1 - Date: 2026-05-13 - Version: 1.30.1 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/1.30.1 - **security** — Address various recent CVEs in Nginx - **changed** — Update to new nginx stable package New nginx stable package. Run apt update && apt upgrade to update. Addresses various recent CVEs in Nginx, see nginx.org for more details. ### 12.21.6 - Date: 2026-05-10 - Version: 12.21.6 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.6 - **security** — Hide 'mailq' and 'postqueue' binaries from customer container - **changed** — Improved cleanup of expired "run in customer container" tasks initiated by WordPress/Joomla toolkit to prevent potential task queue overrun Security Hide 'mailq' and 'postqueue' binaries from customer container. Enhanced Improved cleanup of expired "run in customer container" tasks initiated by WordPress/Joomla toolkit to prevent potential task queue overrun. ### 12.21.5 - Date: 2026-05-08 - Version: 12.21.5 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.5 - **security** — Hide known setuid binaries from website containers to limit attack vectors from local privilege escalation vulnerabilities in the Linux kernel Security Due to the recent local privilege escalation (LPE) vulnerabilities in the Linux kernel targetting setuid binaries (CVE-2026-43284, CVE-2026-43500, CVE-2026-31431, etc), this release now hides known setuid binaries from website containers. This does not make your system immune to such vulnerabilities but it does limit potential attack vectors and would frustrate any attacks originating from a compromised CMS or a malicious customer. ### 12.21.4 - Date: 2026-04-28 - Version: 12.21.4 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.4 - **fixed** — Backup destination is now updated on application and email servers when migrating a website that previously had no backup server set to a new backup server Failure to update backup destination on application/email server when migrating a website which previously had no backup server set to a new backup server. ### 12.21.3 - Date: 2026-04-14 - Version: 12.21.3 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.3 - **removed** — Ability of collaborator role to add or delete Cloudflare tokens via API - **changed** — End user must now supply subscription ID when cloning to a new website via API Removed ability of collaborator role to add/delete Cloudflare tokens via API. End user must supply subscription ID when cloning to a new website via API. ### 12.21.2 - Date: 2026-04-09 - Version: 12.21.2 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.2 - **changed** — Global backup settings are now re-applied on installation of a new Backup role - **fixed** — Improved handling of expired snapshot deletion where directories are missing read or execute permissions - **changed** — Expired snapshot cleanup runs less frequently and on a separate scheduler - **fixed** — File manager can now handle directories which are unreadable due to file permissions All global backup settings are now re-applied on installation of a new Backup role. Improved handling of expired snapshot deletion where directories are missing read or execute permissions. Expired snapshot cleanup runs less frequently and on a separate scheduler. File manager can now handle directories which are unreadable due to file permissions. ### 12.21.1 - Date: 2026-04-04 - Version: 12.21.1 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.1 - **changed** — Increased Let's Encrypt initial connection timeout - **changed** — Improved Polish language pack - **changed** — Altered RPC keepalive strategy for transfer of backup data between servers - **changed** — Built in PHP extensions displayed in website dashboard now include compulsory extensions loaded at runtime in addition to those compiled in to PHP - **added** — Unix username generation for numeric domains of more than 8 characters in length Increased Let's Encrypt initial connection timeout. Improvements to Polish language pack. Altered RPC keepalive strategy for transfer of backup data between servers. "Built in" PHP extensions displayed in website dashboard now include compulsory extensions loaded at runtime in addition to those compiled in to PHP. Unix username generation for numeric domains of more than 8 characters in length. ### 12.21.0 - Date: 2026-04-03 - Version: 12.21.0 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/12.21.0 - **added** — PHP extension manager now allows enabling any extension built or installed within the global extension directory for the chosen PHP version - **added** — Developer tools section now lists built-in PHP extensions in addition to optional extensions - **fixed** — Enabled PHP extensions now persist after server migration - **changed** — Incompatible extensions are now disabled automatically when changing PHP version - **changed** — mod_security is now explicitly disabled for the per-server Roundcube installation on Apache and Nginx web servers - **removed** — Control panel websites can no longer be mapped to a database server - **changed** — New backups are no longer started during a backup migration to improve transfer performance - **changed** — Cleanup of expired snapshots is no longer performed during a backup migration to improve transfer performance - **fixed** — Website backup destination is now performed after a successful transfer of the backup role - **changed** — Improved efficiency and speed of expired snapshot cleanup - **changed** — MySQL 8.4 is now the default version when MySQL is selected due to 8.0 EOL - **fixed** — Prevent excessive logging where the per-server Roundcube website has not yet been created The PHP extension manager under 'Developer tools' > 'PHP' now allows customers to enable any extension that you have built/installed within the global extension directory for their chosen version of PHP, in place of the predefined list. For guidance on how to add additional configurable extensions click here. The "developer tools" section of the website dashboard now lists built-in PHP extensions in addition to optional extensions. Enabled PHP extensions now persist after server migration. When changing PHP version, any incompatible extensions are now disabled automatically. On Apache and Nginx web server kinds, mod_security is explicitly disabled for the per-server Roundcube installation ( https://mail.customerdomain). Control panel websites can no longer be mapped to a database server. New backups are no longer started during a backup migration to improve transfer performance. Cleanup of expired snapshots is no longer performed during a backup migration to improve transfer performance. Website backup destination is now performed after a successful traansfer of the backup role. Improvements to the effiency/speed of expired snapshot cleanup. MySQL 8.4 is now the default version when MySQL is selected due to 8.0 EOL. Prevent excessive logging where the per-server Roundcube website has not yet been created. ### 8.1.34 — PHP packages - Date: 2026-04-02 - Version: 8.1.34 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/8.1.34 - **added** — PHP 8.x packages now include the pgsql and pdo_pgsql extensions, disabled by default All PHP 8.x packages now ship with the pgsql and pdo_pgsql extensions, disabled by default. ### 8.5.4 — PHP packages - Date: 2026-04-02 - Version: 8.5.4 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/8.5.4 - **added** — PHP 8.x packages now include pgsql and pdo_pgsql extensions, disabled by default All PHP 8.x packages now ship with the pgsql and pdo_pgsql extensions, disabled by default. ### 8.3.30 — PHP packages - Date: 2026-04-02 - Version: 8.3.30 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/8.3.30 - **added** — All PHP 8.x packages now ship with the pgsql and pdo_pgsql extensions, disabled by default All PHP 8.x packages now ship with the pgsql and pdo_pgsql extensions, disabled by default. ### 8.4.19 — PHP packages - Date: 2026-04-02 - Version: 8.4.19 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/8.4.19 - **added** — PHP 8.x packages now include the pgsql and pdo_pgsql extensions, disabled by default All PHP 8.x packages now ship with the pgsql and pdo_pgsql extensions, disabled by default. ### 8.2.30 — PHP packages - Date: 2026-04-02 - Version: 8.2.30 - Original notes: https://enhance.com/support/release-notes - Permalink: https://whatsnew.fyi/product/enhance/releases/8.2.30 - **added** — All PHP 8.x packages now include the pgsql and pdo_pgsql extensions, disabled by default All PHP 8.x packages now ship with the pgsql and pdo_pgsql extensions, disabled by default.