Easy Updates Manager Premium icon

3 versions

Easy Updates Manager Premium history.

Every release of Easy Updates Manager Premium is archived here with its changelog, file size, and security scan result. Use the archive to roll back to a stable release or audit what changed between updates.

3 of 3 releases scanned clean
v9.0.21Latest
May 13, 20261.1 MBScanned
Other
  • SECURITY: Fix a non-persistent reflected XSS vulnerability due to a missing validation and output escaping on the "paged" URL argument. This could allow an attacker, who persuaded you to click a personally-crafted link to your site's dashboard whilst you were logged in, to once run harmful JavaScript code. Thanks to Dmitrii Ignatyev for finding and responsibly disclosing this issue.
Improved
  • Improved the delay updates feature to record the timestamp of the first occurrence of available plugin, theme, or core updates early, when their associated transient option is updated.
  • Corrected improper usage of esc_html_e() when preceded by echo
  • Added missing direct file access protection check for 'ABSPATH' to prevent unauthorized access.
  • Get rid of the "implicitly marking parameter $logger as nullable is deprecated" deprecation warning
  • Suppress false positive WordPress.WP.I18n.TextDomainMismatch warning due to different plugin slugs in free and premium versions.
December 10, 20251.1 MBScanned
Improved
  • Safeguard the calls to PHP's unserialize() function by specifying the "allow_classes" parameter to false to prevent code from being loaded and executed due to object instantiation and autoloading
  • Early processing of external update logs is necessary to resolve the issue of the shutdown function being left out when a severe error happens during an auto/manual update through WP-CLI
  • Enhance the notifications to signify the introduction of other plugins that belong to the same plugin family and to align with the new branding/links
  • Ensure all translation functions are called during the WordPress "init" action or later. Invoking translation functions before the "init" action would have led to no translations being loaded, resulting in the original text being returned.
  • Sanitize the list of days setting that is used for scheduling auto-update cron event
  • Remove seasonal (new year, summer, spring and plugin collection) sale notices
November 14, 20241.1 MBScanned
Fixed
  • Misreporting of plugin's update statuses in notification emails, which were labeled "success" instead of the appropriate designation of "failed"
Improved
  • Improve the strategy for using an associative array to filter option default values, aiming to safeguard existing defaults from removal and to prevent the introduction of non-relevant options
  • The notification email should omit any "failed" update status for plugins, themes and translations if they lack the corresponding name and/or version number
  • Improve updates-check anonymisation and randomisation, stripping out further unnecessary data
  • Replace unnecessary calls to maybe_unserialize()

Why archive

Sometimes the latest release isn't the one you need. The archive lets you pin Easy Updates Manager Premium to a known-good version, or roll back while a bug is investigated. Every release stays scanned and reachable.