Changelog

Recent releases. The complete history, all the way back to 1.0.0, ships inside the plugin as changelog.txt, because a full history belongs with the code rather than on a web page nobody scrolls.

1.0.38 is the first release on WordPress.org. Everything below it was written and used on real sites before the plugin was published, which is why the version number does not start at 1.0.0. The history is here because it is honest, not because you need to read it.

1.0.38

  • Naming and structure tidied for the plugin directory. The admin screen's page identifier now carries the plugin's own prefix, so it cannot collide with another plugin's menu. The old unprefixed registration shortcode has been removed: if you were using it, replace it on your registration page with [banginvites_form], which has always been the documented shortcode and behaves identically. The plugin's functions are no longer wrapped in existence checks, so a name collision surfaces as a clear error rather than quietly disabling part of the plugin.
  • Invitations are now restricted to low-privilege, subscriber-like roles. No role that can edit or publish content, or manage the site, can be assigned by an invitation link; membership and client-area roles built on read-level access are unaffected. The role is re-checked at the moment the account is created, so a tampered record or a role that later gained capabilities falls back safely to your default role. See Roles and security.
  • Registration is processed before the page renders rather than while the registration page is being output. On sites where the theme or a page builder sends output early, the post-registration login and redirect could previously fail and the person would not be logged in or moved on. Handling it earlier removes that class of conflict.
  • An accepted invitation can no longer be flipped back to Pending by generating a new link for it, which was previously possible from a stale Tracking tab. Send a fresh invitation instead.
  • Every settings screen with more than one section now has an "On this page" index down the side that tracks where you are as you scroll and jumps to any section when clicked. Below a narrow width it becomes a row of pills above the content.

1.0.35

  • Stronger cache prevention on invitation links, covering every class of cache: no-cache headers for standards-respecting caches and CDNs, the DONOTCACHEPAGE constant for WordPress caching plugins, a dedicated header for LiteSpeed servers, and a session cookie for platform caches that override the site's own headers, 20i's StackCache among them. This is the same layered approach WooCommerce uses to keep checkouts out of caches.

1.0.34

  • Invitation links are never cached. Page caches were able to serve a stale copy of the registration page from before an invitation was accepted, so a used single-use link could keep showing the registration form to logged-out visitors.
  • Re-inviting an address now clears its old accepted record too, so Tracking no longer shows a stale Accepted row beside the fresh Pending invitation.
  • Deleting a WordPress user now clears their accepted invitation record, so Tracking never shows Accepted for an address with no account behind it. Pending invitations for that address are left live, so the person can use their link again.

1.0.33

  • Housekeeping for the plugin directory. All admin and front-end CSS and JavaScript now goes out through WordPress's own enqueue system against a registered handle. The admin's Inter font is served as four ordinary font files rather than being encoded into the stylesheet on every page load.

1.0.32

  • New admin logo heading the plugin screens.

1.0.31

  • Settings tab tidy-up. The shortcode now appears exactly once, as a click-to-copy chip under the registration page selector, where it used to be mentioned three times. Cards are reordered to follow the setup flow, and the invitation-only protection toggle moved to the Pages card, since that is what it protects.

1.0.30

  • Works alongside other registration plugins. A new Registration method choice lets you keep your own form on the registration page while invite links, expiry and tracking stay exactly the same. The invitation is marked accepted the moment the other plugin creates the account, and the page itself validates every link on load, so single-use enforcement no longer depends on the built-in form. See Using another registration plugin.

1.0.29

  • Review fixes. Silencing WordPress's own account emails no longer triggers PHP warnings on PHP 8. A custom post-registration destination on another domain now actually redirects there instead of silently falling back to the dashboard. Tracking no longer offers Copy link on an expired invitation, since that link is dead.

1.0.28

  • Clear "already signed up" handling. Somebody who revisits a used invite link now sees a plain explanation with a Log in button pointing at your chosen login page, instead of the generic invalid-or-expired notice. The same applies when an account already exists for the invited email. A logged-in visitor gets a Go to your client area button. All of these notices share one branded style, tinted from your registration button colour.

1.0.27

  • Fixed the Role shown in Tracking for people brought over from the old theme-based invites. Tracking now reads each person's live account role where an account exists.

1.0.26

  • The registration form now matches your brand on the front end. The input focus outline and glow use your chosen registration button colour instead of the plugin's fixed indigo, and the invitation-only notice is tinted from that same colour.

1.0.25

  • Added {first_name} and {last_name} tokens to the welcome email, with click-to-insert chips, so you can greet people by either name part on its own.

1.0.24

  • Added a setting for where clients log in: the standard WordPress login, any page on your site, or a custom URL. The welcome email's Log in button and {login_url} link follow this choice.

1.0.23

  • Fixed: the welcome email and the admin new-registration notification never sent. They were queued after WordPress had already passed the point where they were meant to fire. Both now send reliably the moment a registration completes.

1.0.22

  • Restored the full plugin name and matched it across the plugin header and readme.

1.0.21

  • WordPress.org compliance pass: escaping, sanitising and unslashing of all remaining form inputs, prefixed uninstall variables, and a trimmed short description. No change to features or behaviour.

Earlier

1.0.20 back to 1.0.0 cover the plugin's development: generated usernames replacing a username field, separate first and last name fields, the toolbar shortcut, invitation-only page protection, the rich editor for both emails, token chips, the floating save bar, and in 1.0.0 the first working version with expiring single-use links, role selection, tracking and both emails. All of it is in changelog.txt inside the plugin.

Still stuck?

Write to me and it is me who answers, not a ticket queue. Tell me what you expected and what happened instead.

Ask a question

Bang! Creative Family

Bang! Plugins is part of a small UK creative group, so the plugins are made and backed by people who do this for a living.