Changelog · since v1.0.0

Changelog.

Every release, every change. Grouped by type so you can scan for the bit that matters: a new tool, a polish pass, a quiet fix. The auditor era below covers the audit engine; the earlier reporting era is kept as one note at the end.

CURRENT RELEASE
v2.6.6.
JULY 21 2026 · 7 DAYS AGO
LATEST
RELEASES
46
CHANGES (V2)
98
FIRST RELEASE
Jan 2025
CADENCE
Continuous
The auditor era · fifteen releases
SHOW
v2.6.6.
JULY 21 2026
LATEST
4 IMPROVED

The Frontend Auditor shows the exact address that’s broken, and the activity log keeps a complete record.

A polish release across the auditor and the log. A broken link or image in the Frontend Auditor now shows the dead address itself, a dead internal link offers “Edit page” as well as “Create redirect,” and every activity-log entry expands to a complete, copyable record.

IMPROVED 4 CHANGES
  • The Frontend Auditor now shows the broken address itself. Open a broken image, link or dead internal link and its detail box now displays the exact URL at fault — the image’s source or the link’s address — so you can see what to fix without hunting for it. A dead link on your own site also offers an “Edit page” button that opens the exact post the link lives on, alongside “Create redirect.” PRO
  • Every activity-log entry expands to its full record. Entries logged without extra context — a maintenance pass, a licence check — used to expand to a one-line explanation; every entry now leads with its core record (who acted, the action and the level), so the Copy button always yields a complete, self-contained receipt.
  • The Frontend Auditor reads more cleanly. Its fix-preview guidance now uses the body font instead of monospace (literal URLs and paths stay monospace where alignment helps), it no longer inherits a theme’s letter spacing, its buttons no longer underline on hover, and each protection’s toggle sits centred against its label. PRO
  • Your AI settings stay visible when AI is off. The provider, model, API key and cap fields used to vanish when the AI master switch was off; they now stay on screen, greyed and inactive, so what’s configured is clear at a glance. Your saved settings are preserved exactly as before.
v2.6.5.
JULY 19 2026
3 IMPROVED

A leaner, fully self-contained free build, and the Frontend Auditor completes the “Ledger” redesign.

A compliance and polish release. The free download is trimmed to exactly what it uses — no code for features it does not expose, and no outbound network calls at all — the Frontend Auditor moves to the “Ledger” design so every screen reads as one system, and one file-hardening check becomes detect-only.

IMPROVED 3 CHANGES
  • The free build is now fully self-contained. It carries none of the Pro-only machinery it never used and makes no outbound network calls at all, matching its promise that nothing about your site is sent anywhere. Both downloads are also about half the size, having dropped a megabyte of unused preview images left over from the retired report feature.
  • The Frontend Auditor moves to the “Ledger” design, completing the redesign. The in-page auditor that floats over your live pages now matches the rest of the admin — warm paper, navy ink and a single gold accent — and works exactly as before. PRO
  • The “Exposed install file” check is now detect-only. Rather than deleting the default files that reveal your version (readme.html, license.txt, wp-config-sample.php), RecapWP now flags them and explains how to remove them yourself through your host’s file manager or SFTP. Reinstalling WordPress restores any you ever need back.
v2.6.4.
JULY 17 2026
2 NEW 1 IMPROVED 2 FIXED

Your health score and full activity log come to Free.

A Free/Pro rebalancing. Your site’s health score and its history, and the activity log’s who-did-what columns and filters, all read your own site, so they now belong to you on Free. Pro keeps the security-event stream: the record of sign-ins and of user, role, plugin and theme changes.

NEW 2 CHANGES
  • Your health score and score history are now in Free. Both were always calculated for every site, then covered with an “Included with Pro” sticker. Your score is a reading of your own site, so it belongs to you: the Dashboard plate, the Audit plate and the Score history panel all show real numbers on Free.
  • The activity log’s Actor and Action columns come to Free. Who did what, on every site, with a filter for each, plus attribution for clearing the log and saving settings, so “who cleared the activity log?” always has an answer.
IMPROVED 1 CHANGE
  • Pro’s security-event recording is cleanly separated out. Sign-ins, user and role changes, and plugin and theme changes are recorded by a Pro component the free build no longer carries at all, rather than shipped and switched off, so nothing visible changes and the free download is leaner. PRO
FIXED 2 CHANGES
  • Activating on a brand-new site is clean again. First-time activation could report “unexpected output” because RecapWP tidied up records from older versions before it had created the tables those records live in; it now builds its tables first and tidies afterwards. Existing sites were never affected.
  • The update screen no longer describes a retired feature. The Pro update panel still advertised the long-gone monthly email reports (retired in 2.4.0); it now reads its description from the plugin itself, so it cannot drift out of date again.
v2.6.3.
JULY 17 2026
5 NEW 3 IMPROVED 1 FIXED

The admin is remade in the “Ledger” design, and three more security protections land.

The largest visual release since the pivot. Every one of the nine admin screens, Dashboard through License, moves to a single navy-and-gold “Ledger” design that reads as one system. Alongside it: three more Security protections, findings that open to their full detail and walk you to what needs attention, and internal-link checks that now see your WooCommerce catalog.

NEW 5 CHANGES
  • Three more Security protections. Disable the file editor and Hide login error details join the Security group in both Free and Pro, plus Disable Application Passwords in Pro. Each is a switch you flip on and leave on, reversible like the rest, and re-checked at every audit; if your site already has one in place, it reads as “in place” rather than an off switch.
  • File editing in wp-admin is now a fixable finding, not just a warning. The built-in Appearance and Plugins file editor, which lets any administrator run PHP straight from the dashboard, can be turned off in one click and back on with Undo. RecapWP applies it at runtime with no wp-config.php edit, so it is a plain reversible switch like the other hardening fixes. Ships in both Free and Pro.
  • “Snooze until next audit” returns to findings. A lighter “not now” than Mark OK: snoozing hides a finding from the open list and your Health Score for one cycle, then the next scan decides automatically, if it is still there it returns, if it is gone it closes for good.
  • Findings now open to their full detail, and walk you to what needs attention. Every row shows why it matters, exactly what acting does, and when it was found; an area holding a single finding opens it straight away; and Review on the Dashboard scrolls to the finding and slides it open, so it is clear where you have landed.
  • Internal-link checks now see your whole catalog. The orphaned-content and dead-end checks, and the Internal Links report, now cover WooCommerce products and public custom post types, so a hidden, unlinked product surfaces as a lost-sales orphan instead of staying invisible. PRO
IMPROVED 3 CHANGES
  • All nine admin screens now share the “Ledger” design. Dashboard, Audit, Protection, Redirects, Broken Links, Internal Links, Logs, Settings and License: a navy masthead, a plain-English headline, live counts and self-hosted fonts with no external requests, every screen reading as part of one system. The License screen was the last to move, completing the redesign.
  • The Audit scan is now a narrated, area-by-area sequence. One area scans at a time with a pinned progress bar you can watch, and cancel, from anywhere on the page; when the link crawl is in scope it counts real pages live, and the audit will not report complete until the crawl actually finishes.
  • Reversible audit actions are now direct, with no “are you sure?” step. Applying a fix, marking a finding OK, snoozing it and undoing all act immediately and roll back cleanly if the server rejects them. The only dialog left is the redirect target editor, which still checks the destination is live before it saves.
FIXED 1 CHANGE
  • The Dashboard only lists findings the Audit can actually show. A few leftover SEO items from before on-page SEO moved into the Frontend Auditor could sit on the Dashboard forever behind a Review button that led nowhere; they are retired automatically when you update, and Review now always lands on a real finding.
v2.6.2.
JULY 5 2026
1 NEW 2 IMPROVED 2 FIXED

Two file-security fixes come to Free, and deleting the plugin is a clean uninstall.

A Free/Pro housekeeping release. The two one-time file-security fixes are now in the Free version, the runtime-enforced Pro fixes now honestly follow the license, and deleting the plugin always reverts every fix and removes every trace, with no opt-in switch to remember.

NEW 1 CHANGE
  • Two file-based security fixes are now in Free: deleting exposed install files (readme.html, license.txt, wp-config-sample.php) and tightening insecure file permissions (wp-config.php, wp-content, uploads and the site root) used to be Pro-only. They fit Free because each is a permanent one-time change with nothing to keep enforcing.
IMPROVED 2 CHANGES
  • Pro’s runtime-enforced fixes now follow the license: the Performance tune-ups, the REST and feeds hardening, login protection and the redirect engine stop enforcing when a license lapses or the Pro plugin is removed, and resume the moment Pro is back, settings intact, no re-scan needed. The Free security basics and the file fixes keep working regardless of license. PRO
  • Deleting the plugin is now a clean uninstall, always: it reverts every applied fix (returning the site to its pre-fix state), removes all RecapWP data, and frees the license seat. The old off-by-default “Delete all data” setting is gone. Deactivating still changes nothing; only an explicit Delete wipes.
FIXED 2 CHANGES
  • Deleting Pro alongside an active Free now cleans up fully: the Lemon Squeezy license seat is released for reuse, and the uninstall no longer crashes on the two builds’ shared classes. PRO
  • Fixes applied under Pro can always be reverted, even on Free: after a downgrade or a license lapse, “Revert all fixes” now undoes everything Pro applied, restoring the exact option, file or redirect rule from RecapWP’s own change ledger. Undo is never blocked by your plan.
v2.6.1.
JULY 5 2026
10 NEW 8 IMPROVED 5 FIXED 2 REMOVED

Protections become switches, link health gets its own tools, and the scan is instant.

The biggest release since the pivot, built around one idea: with RecapWP’s audit engine it is now easier than ever to keep a WordPress site healthy and secure. A new Protection page turns every standing protection into an on/off switch, the broken-link crawl moves to its own Broken Links tool (making the Audit’s “Scan now” near-instant), a new Internal Links report maps how your pages connect, redirects gain response types, and a long reliability and polish pass lands across the whole admin.

NEW 10 CHANGES
  • The Protection page: every protection is a switch. A new tab lists every standing protection RecapWP can manage (13 in Pro: 7 Security, 6 Performance; Free shows its core Security set), each as a simple on/off toggle you can flip any time, no scan required. Turning one on applies it through the same reversible machinery as an Audit fix; you’d only turn one off when it conflicts with something (say, an app that needs XML-RPC). Fixes applied, “already in place” states and Marked-OK items live on the same page, so everything RecapWP has handled is visible at a glance.
  • The Broken Links tool: the page crawl moved off the Audit’s “Scan now” onto its own tool page: choose what to crawl, run it, and watch broken links stream in live, each row expandable to every page the dead link appears on, with Create redirect and Mark as OK right on the row. PRO
  • The Internal Links report: a read-only map of how your pages connect: inbound, outbound and external link counts for every page the crawl saw, orphan pages and dead ends flagged, searchable, sortable and filterable, with every term explained in place. PRO
  • Internal-link health checks with suggestions: the Links area now flags dead-end pages (they receive links but pass none onward) and under-linked posts, each finding listing a few topically-related posts you could link from, computed deterministically. Advisory only: RecapWP never edits your content. PRO
  • Redirect types: 301, 302, 410 and 404. Everywhere you create a redirect now offers Permanent, Temporary, Gone and Not-found. A gone type needs no target (the honest choice when there is no live page to send visitors to), and a 301/302 now requires a live target before it can be created. PRO
  • Broken-redirect detection: a redirect you set up whose target has since died is caught even when nothing on the site links to it, flagged as high severity (real traffic is landing on a dead page), and fixable in place by repointing it to a live target, hit count preserved. PRO
  • Five reversible performance fixes: remove jQuery Migrate, throttle the admin heartbeat, clean up the page head, and render Google Fonts faster with display-swap and preconnect. Each is a switch, each undoable, and none touches a file. PRO
  • Ten new per-page checks in the Frontend Auditor: Open Graph and Twitter Card tags, the canonical link, duplicate H1s, viewport meta and favicon, plus four accessibility checks (positive tabindex, unlabelled buttons, image-only links, a missing skip link), each with plain-English fix guidance. An SEO plugin that already injects the tags satisfies the checks automatically. PRO
  • Every finding explains why it matters: each finding row now carries a one-line, plain-English consequence (“A common brute-force entry point,” “Old revisions bloat the database”) beside what it is and how urgent it is, so you never have to guess why something was flagged.
  • Two server-health advisories: the Environment area now flags PHP OPcache being off and a low PHP memory limit. Detect-only, since they’re server settings; the memory check only fires below 128 MB, so it never nags a well-provisioned site.
IMPROVED 8 CHANGES
  • “Scan now” is instant: with the crawl on its own tool, an Audit scan is a fast synchronous pass that finishes in seconds, unless you put Links in scope, in which case the crawl runs in the background with live progress that follows you to any RecapWP page.
  • A tidier nav: the tab bar is now Dashboard · Audit · Logs · Settings · License, with Protection, Broken Links, Internal Links and Redirects grouped under the Audit menu, one hover away from any page.
  • A self-tuning crawler with consistent results: the crawl adapts its speed to your server automatically, and an external link that times out gets one longer-timeout re-check before the verdict sticks, so the broken count no longer varies between runs. PRO
  • Broken-link detection catches every genuine error: any real client or server error now flags as broken, and a dead external host is caught too, while auth walls, rate limits and bot challenges deliberately stay off the list, so the auditor never cries wolf. PRO
  • Visitor-404 noise is gone: dead URLs that bots and scanners probe (but that nothing on your site links to) no longer clutter the Audit or the Broken Links tool; both list only links actually found on your pages. PRO
  • “Turn off” for protections, “Revert” for fixes: an on/off protection now offers Turn off (you’d only use it on a conflict), while a corrective fix like a created redirect or a restored file offers Revert. The honest verb for each kind of change.
  • Broken images and files are Content findings: a broken image or a dead file link is a content problem (re-upload the file or fix its address in the editor), not a redirect problem, so it now lives in the Content area with a Review action. PRO
  • Clearer, more honest copy throughout: area descriptions were corrected to what each area actually checks, finding titles no longer show raw URLs or repeat their reason twice, the Mark-OK dialog is accurate for advisory findings, and “safe” was dropped as a fix qualifier.
FIXED 5 CHANGES
  • The Frontend Auditor reliably flags dead internal links again: genuinely dead links surface dependably on any host, while a link WordPress itself redirects to a live page is classified as a redirect, not broken. PRO
  • Crawls can no longer freeze or wedge: on a host whose background cron doesn’t fire, the open tab now drives the crawl itself; an interrupted crawl clears its stuck “Scanning…” state automatically, and a wedged job is discarded so a fresh scan can always start. PRO
  • “Found on N pages” no longer under-counts: a page that failed one fetch during a crawl is retried instead of silently dropped, so every source page of a broken link is credited and a link hosted only on that page is never missed. PRO
  • Deleting a redirect reopens its finding: removing a RecapWP-created redirect from the Redirects tab now returns the underlying broken link to the open list, instead of leaving it stranded as “fixed” by a redirect that no longer exists. PRO
  • Responsive and dark-mode polish across the admin: no page scrolls sideways on tablets or phones any more (wide tables reflow into cards), the status strip collapses gracefully on small screens, and the low-contrast dark-mode blues were brightened.
REMOVED 2 CHANGES
  • Turbo mode: the manual full-throttle crawl switch is gone. The crawl now tunes itself to your server automatically, which is also what made results consistent between runs: Turbo could overdrive a small server into timeouts that under-counted broken links. PRO
  • The standalone internal-links scan: the Internal Links report no longer has its own scan button; it refreshes from any full crawl (the Broken Links tool, or an Audit with Links in scope). PRO
v2.6.0.
JUNE 28 2026
2 NEW 3 IMPROVED 1 FIXED 1 REMOVED

On-page SEO moves to the Frontend Auditor; the crawl goes links-only.

On-page SEO detection moved out of the bulk Site Audit and into the per-page Frontend Auditor, where you see and fix each issue in context. The Site Audit is now 42 deterministic checks across 9 areas, the broken-link crawl is a pure links and orphan-page pass, and the Content area focuses on stale posts. A link-checker fix also stops live, theme-rendered pages from being mis-flagged as broken links.

NEW 2 CHANGES
  • A configurable stale-post cap: Settings → Scan limits → Maximum stale posts to list sets how many stale posts the Content area surfaces per scan (default 100, range 10 to 1,000). Posts are listed most-stale first, so the cap always covers the oldest. PRO
  • A single “Scan limits” settings section: the crawl page cap and the new stale-post cap now live together in one Pro section, since both govern how much a capped area covers per scan. PRO
IMPROVED 3 CHANGES
  • On-page SEO moved to the Frontend Auditor: missing meta descriptions, missing image alt text, and thin content are no longer a bulk scan area. The Frontend Auditor flags them per page as you browse, where you can edit the offending image or post directly. PRO
  • The broken-link crawl is now links-only: with on-page SEO handled per page, the crawl no longer reads each page’s meta description. It is a pure broken-link and orphan-page pass, so each crawled page is a touch lighter. PRO
  • The Content area now covers stale posts only: aging posts that may want a refresh. Thin content moved to the Frontend Auditor with the rest of the on-page SEO signals.
FIXED 1 CHANGE
  • Live pages are no longer mis-flagged as broken links: on sites whose blog or other sections are served by theme templates as virtual routes rather than real WordPress posts, the link checker could report a live page as a broken internal link. An unresolved same-site link is now treated as unknown, and reported broken only when a real request confirms a genuine error. PRO
REMOVED 1 CHANGE
  • The standalone SEO scan area: the SEO domain and its three checks (missing meta description, missing alt text, thin content) were removed from the Site Audit engine. The signals live in the Frontend Auditor now.
v2.5.5.
JUNE 28 2026
2 NEW 1 IMPROVED

A configurable crawl page cap, and honest coverage on large sites.

The broken-link crawl’s page limit is now a Pro setting, and the content-types picker is upfront about partial coverage when a site has more pages than the cap.

NEW 2 CHANGES
  • A configurable crawl page cap: Settings → Broken-link crawl → Maximum pages per scan sets how many pages a crawl visits (default 5,000, range 10 to 25,000). Pages are crawled most-important-first, so the cap always covers your top pages; raising it lets a large site cover its full long tail in one pass. PRO
  • An honest crawl-coverage note: when a site has more crawlable pages than the cap, the content-types picker shows “Covers the first N of M pages, most important first” with a link to raise the limit, so partial coverage is visible up front. PRO
IMPROVED 1 CHANGE
  • The Free build strips the new crawl-page-cap setting: the crawl is Pro-only, so its setting and section are removed from Free.
v2.5.4.
JUNE 28 2026
1 FIXED

A dark-mode fix for the License key field.

A CSS-only fix so the License key field keeps its dark styling even when an admin theme or another plugin restyles text inputs.

FIXED 1 CHANGE
  • The License key field no longer renders as a light box: on sites whose admin theme or plugins restyle text inputs with a higher-specificity or !important rule, the dark License key card’s field could flip to a light background with dark text. Its styling is now re-asserted so no theme or plugin can override it. CSS-only. PRO
v2.5.3.
JUNE 28 2026
2 IMPROVED 1 FIXED

Daily license revalidation and a copy cleanup.

Pro license checks move from weekly to daily so a cancelled or expired license is enforced within about a day, with new safeguards so a brief Lemon Squeezy outage can’t wrongly downgrade a paying site. The customer-facing copy also drops “safe” and “one-click” as fix qualifiers, since every fix is already reversible.

IMPROVED 2 CHANGES
  • Pro license revalidation now runs daily: the license re-check moved from a weekly to a daily cadence, and the schedule is self-healing, so existing installs migrate to daily on a plain plugin update. A cancelled or expired license is now enforced within about a day instead of up to a week. (Free has no license and is unaffected.) PRO
  • Cleaner fix copy: “safe” and “one-click” were dropped as fix qualifiers across the admin and the marketing-facing strings, since fixes are reversible by design and the labels stated the obvious. Wording that explains a real constraint (for example, only a same-site http→https upgrade) was left intact.
FIXED 1 CHANGE
  • A transient outage can no longer revoke a paying license: now that checks run far more often, a Lemon Squeezy rate-limit or server error is treated as a temporary failure with a grace window (about three days) rather than read as “invalid” and revoked on the spot. A genuine cancelled or invalid verdict still downgrades immediately. PRO
v2.5.2.
JUNE 28 2026
1 NEW 3 IMPROVED 1 FIXED

WordPress.org compliance: the Free build now ships zero Pro code.

A WordPress.org readiness pass. The Free build now physically removes every Pro feature rather than shipping it dormant, deleting the data “Delete all data” now frees the Lemon Squeezy seat on a Pro site, and the WordPress.org Plugin Check passes clean.

NEW 1 CHANGE
  • “Delete all data” frees your Pro seat: when a Pro site is deleted with full data wipe enabled, the uninstaller now deactivates that site’s Lemon Squeezy activation before erasing the license key, releasing the seat for reuse. It runs only on the full-wipe path and is fail-safe, so it can never block deletion; the normal data-preserving delete deliberately keeps the activation so a reinstall stays Pro. PRO
IMPROVED 3 CHANGES
  • The Free build ships zero Pro code: WordPress.org prohibits shipping locked features even when inert, so the Free build now physically strips them, removing the five Pro auditor areas (Errors, Performance, SEO, Content, WooCommerce), the twelve Pro Security checks, and the Ask RecapWP assistant along with its admin surfaces and Pro JavaScript. Pro is unchanged.
  • A clear Free name on WordPress.org: the Free build’s display name is now “Recap Site Auditor” (it previously read as a generic name a reviewer flagged); the slug and text domain stay the same.
  • Tidier shipped code: the comment-stripping step in both builds now removes a comment’s whole line and trims trailing whitespace, and the Pro plugin description was updated to the current auditor positioning (dropping the retired monthly-recap claim).
FIXED 1 CHANGE
  • Plugin Check passes clean on the Free zip: every error and warning the WordPress.org Plugin Check raised was resolved, including translator comments on the placeholder strings, a corrected file-operation sniff name, input-unslashing on the kept Free AJAX readers, and the removal of two orphaned hardening fixers that shipped as dead code.
v2.5.1.
JUNE 27 2026
1 IMPROVED 3 FIXED

Free becomes a focused hardening teaser, plus three fixes.

The Free build was re-scoped around core security hardening: Errors, Performance, SEO and Content moved to Pro, and Security now shows the hardening basics in Free with the deeper checks reserved for Pro. Users, Platform and Environment stay in Free. Three display fixes round it out.

IMPROVED 1 CHANGE
  • Free is now a focused hardening teaser: Errors, Performance, SEO and Content moved to Pro. Free Security keeps the core basics (XML-RPC exposure, version exposure, username enumeration, security headers, HTTPS and mixed content, browsable uploads), while the deeper checks (file permissions, core integrity, exposed install files, SSL-expiry, login protection and the REST/feeds advisories) move to Pro. Net Free is Security plus Platform, Users and Environment; Pro is unchanged.
FIXED 3 CHANGES
  • No more accent-stripe flash on load: the thin gradient accent stripe on the Site Health hero, Dashboard hero, Ask card and scan dock briefly overshot the card’s rounded corner on the first painted frame and then snapped into place. It now clips its own corner, so it follows the curve from the first frame.
  • Stale-content findings no longer show “last updated” twice: the stale-post check put the modified date in both the finding label and its detail line, doubling it. The label is now just the post title, with the date shown once.
  • The “Free version is paused” notice is legible in dark mode: its body text had no dark-mode color and inherited a dark grey on the dark card; it now uses a light ink.
v2.5.0.
JUNE 27 2026
1 IMPROVED

Engine and reliability groundwork, behind the scenes.

An under-the-hood release: internal engine and background-job reliability work that lays groundwork for future detection, with nothing new to see in the audit yet.

IMPROVED 1 CHANGE
  • Background-job and engine groundwork: reliability and infrastructure work behind the scenes, laying groundwork for future detection, with no user-facing changes in this release.
v2.4.1.
JUNE 26 2026
4 NEW 4 IMPROVED 4 FIXED

A full dark theme, “Revert all fixes,” and a sharper Free build.

The first follow-up to the pivot. The whole admin gains a proper light/dark theme behind one toggle, Settings gets a “Revert all fixes,” the assistant now shows your findings and logs inline instead of pointing at a tab, and the Free build’s auditor split was tightened so a Free scan runs cleanly.

NEW 4 CHANGES
  • Global light/dark theme: the whole admin UI now has a proper dark version, flipped by a single sun/moon toggle in the page header. It replaces the three separate in-card toggles with one site-wide preference that renders with no flash and switches live, no reload.
  • “Revert all fixes”: a new Settings action undoes every fix RecapWP has applied in a single pass, newest first, returning the site to its pre-fix state through the same per-finding undo path as the Audit tab. A red confirm spells out the consequence; the button reads “no applied fixes to revert” when there’s nothing to undo.
  • The assistant shows your data inline: ask for your latest logs, open findings, or redirects and Ask RecapWP renders the real list right in the chat, pulled from the same stores the rest of the plugin uses, instead of telling you which tab to open. PRO
  • Redirects manager polish: a dedicated colour-coded Status column shows each target’s live HTTP status, every rule shows when it was added, the add form is keyboard-driven (Enter to check, Enter again to add), and each log context block has a copy button. PRO
IMPROVED 4 CHANGES
  • The Free build’s auditor split is encoded: Free now ships full detection across the non-crawl areas plus all the fixes with Undo and “Revert all fixes,” while the broken-link crawl, Links and WooCommerce areas, redirect manager, Frontend Auditor, login guard, audit-log enrichment, and assistant stay Pro.
  • The assistant knows this site again: Ask RecapWP was re-grounded in the live audit: your health snapshot, top open findings, open issues by area, active redirect rules, and recent activity, with a rebuilt slash menu (/scan, /health, /fix, /security, /redirects, /improve). It now cites specific findings and leads with the highest-severity ones. PRO
  • Frontend Auditor refined: the live per-page inspector reverts to the name “Frontend Auditor” everywhere it shows, and its floating launcher now mirrors the inspector panel’s own chrome, following the panel’s light/dark switch and remembering it across page loads. PRO
  • Plugin updates are now “Review,” and bot probes are collapsed: updating a live plugin from the audit is too high-blast-radius to apply automatically, so plugin updates are detect-only with a Review affordance, and the constant recon 404s automated scanners generate are folded into one penalty-free “N suspicious 404s (likely bots)” advisory instead of cluttering the list.
FIXED 4 CHANGES
  • Free scans no longer fail with “Server busy”: the Free build was still trying to start the Pro-only page crawl, which the server answered with repeated 400s and a misleading busy-server toast. The crawl is now gated on Pro, so Free runs the synchronous audit pass cleanly.
  • Redirect status follows the chain: a rule whose target was itself a redirect into a dead end used to show a false 200; the status resolver now follows the chain to its final destination (loop-guarded) and reports the real code. PRO
  • A bot-blocked external link isn’t called “broken”: an outbound link returning 403/401/429/5xx is reachable, just refusing automated requests, so the auditor now flags an external link only when it’s genuinely gone (404/410) or unreachable. PRO
  • A never-scanned site reads honestly: the Dashboard and Audit Site Health heroes now show “No scan yet” with a blank score and dashed-baseline trend instead of a meaningless 100/Excellent or a false “Scan in progress…”
v2.4.0.
JUNE 22 2026
5 NEW 2 IMPROVED 4 REMOVED

The pivot: RecapWP becomes a site auditor and fixer.

RecapWP stopped being a monthly-report plugin and became a WordPress site auditor and fixer. The entire report subsystem was retired and deleted; in its place, an on-demand “Scan now” runs 45 deterministic checks across 10 areas, shows what’s wrong worst-first, and fixes them for you, each one reversible, with a one-action “Revert all fixes.” No AI is involved in finding or fixing anything.

NEW 5 CHANGES
  • The Site Auditor: an on-demand “Scan now” runs 45 deterministic checks across 10 areas (Security, Platform, Performance, SEO, Links, Content, Users, WooCommerce, Environment, Errors), lists findings worst-first, and fixes them for you. Every fix is backed by an apply/undo ledger, so any fix is reversible and the whole set rolls back with “Revert all fixes.”
  • File-security hardening checks & fixes: file-permission flags with a chmod fix, core-file integrity against the official WordPress.org checksums, exposed install files (readme/license/sample config) with a delete fix, and a missing uploads index, plus security headers, REST and feed advisories, each on the deterministic detect → fix-with-undo model.
  • Redirect system & 404 monitor: a dead URL becomes a 301: a visitor-404 monitor records the dead URLs real visitors hit (bots filtered out), surfaces them as findings, and the “Create redirect” fix writes a same-site 301 with Undo. A new Redirects manager lists every rule with hit counts and last-hit time. PRO
  • Frontend Auditor: when an administrator views a page on the front end, a live client-side inspector scans the rendered DOM and pins findings on the page (contrast, broken images, captured JS errors, heading order, missing alt/meta, broken and redirected links), with a real “upgrade to https” fix and a Mark-OK lifecycle. PRO
  • An audit-focused Dashboard: the report-era dashboard was replaced with a Site Health hero (score gauge + scan readout), a Recent activity timeline, an On-Page Auditor feed, a Score-trend sparkline, and a “Recently fixed” panel, plus a four-tile KPI row (Needs action, Fixed, Protections, Failed logins).
IMPROVED 2 CHANGES
  • The Health Score tracks what warrants attention: only Critical, High and Medium findings now move the 0–100 score; Low and Info stay advisory (still listed, but no longer able to drag an otherwise-healthy site into “Needs attention”).
  • “Areas,” consistently: the scan scope picker now lists the same 10 curated areas shown everywhere else (rather than the raw scanner domains), and two were renamed for clarity: Updates → Platform and Platform → Environment.
REMOVED 4 CHANGES
  • The entire monthly-report subsystem: retired and deleted, not gated: monthly email reports, the report builder and email sender, the 7 email templates and the annual Year-in-Review, the Health Score narrative, smart commentary, and month-over-month comparisons. A migration drops the report database tables on upgrade.
  • White-label: it only ever themed the now-deleted report emails, so the agency-identity settings, logo uploader, brand-color picker, and email-identity options were all removed.
  • The scheduler surface and daily collection: the auditor is manual-scan plus always-on capture, with no recurring scan cron, so the report-era daily-collect and monthly-send jobs, the scheduler status pill, and the no-scheduler notice are gone (only the Pro weekly license check remains).
  • The report-era Settings stack: Settings was slimmed from nine report/white-label sections down to three: AI (connection only, for the assistant), Logging (audit-log retention), and Uninstall (data retention).
No changes of this type in the auditor era. Switch the filter to see the rest.

The v1 era · monthly reports.

Before the audit engine, RecapWP was a monthly WordPress reporting plugin: collect the month’s numbers, render a branded email, send it on schedule. Seventeen feature releases, kept here for the record.

v1.7.0 JUN 1, 2026 AI report intelligence: an in-admin assistant, AI-written report copy and subject lines, redesigned templates, one-click Pro updates.
v1.6.0 JUN 1, 2026 Bring your own model: connect any OpenAI-compatible provider and RecapWP writes each report's executive summary.
v1.5.8 MAY 31, 2026 Sealed Recap template, smarter cron monitoring with an "overdue" state, and free-edition Send now / Collect now controls.
v1.5.7 MAY 30, 2026 Data-safety fix for running the free and Pro editions side by side: cleanup waits for the last RecapWP plugin.
v1.5.6 MAY 29, 2026 Data kept by default on delete, a free edition on the way to WordPress.org, full Pro template previews.
v1.5.5 MAY 26, 2026 Pro logging, recipient defaults, first-install Pro setup, locally bundled fonts, and seven fixes.
v1.5.4 MAY 25, 2026 Export CSV, fourteen new PageSpeed and uptime metrics, white-label across every template.
v1.5.3 MAY 25, 2026 All seven templates wired to real data; custom post types, taxonomies, and users-by-role modules.
v1.5.2 MAY 25, 2026 Automatic first-install collection, a comprehensive timezone pass, and the Logs tab.
v1.5.1 MAY 24, 2026 The v1.5 brand refresh: Period Mark logo, Dashboard Health Hero, email dark mode.
v1.5.0 MAY 24, 2026 Brand color derives a five-stop palette every template adapts to: cover, charts, borders, fills.
v1.4.0 MAY 24, 2026 White-label header colors: custom header background and font-color mode.
v1.3.0 MAY 24, 2026 White-label PRO: agency identity across every surface. Your logo, your color, your From address.
v1.2.0 MAY 23, 2026 Health Score (eight-factor composite), month-over-month comparisons, agency digest, annual Year-in-Review.
v1.1.1 MAY 23, 2026 Cleanup: template files renamed to descriptive slugs matching the UI labels.
v1.1.0 MAY 23, 2025 Template preview system, inline report viewer, and the WooCommerce module toggle.
v1.0.0 JAN 1, 2025 Initial release: the full reporting framework. Five tabs, daily collection, seven templates, Lemon Squeezy licensing.
START OF HISTORY · v1.0.0

Open a standing record of your site’s health.

Install RecapWP, run your first audit, and see everything it finds before deciding on a single fix.

Get RecapWP Pro → first audit takes about a minute