pkg_subsmgr changelog

Notable releases and milestones for Subscription Manager (pkg_subsmgr).

VersionSummary
4.5.68 (production) Review card buttons work on cached sites. Maybe later and Don’t ask again now dismiss the “Leave a review on the JED” card on sites with caching on; previously the card could come back on the next page load. Old pricing links still land on prices. A pricing link that names an extension under its former component name (for example com_veriform, on this site is which is now the pkg_veriform package) is redirected to the package’s pricing page with the chosen tier kept, rather than showing a “get in touch” card with no prices. A link for an extension that does not exist goes to the directory with a notice.
4.5.66 (production) Trial to paid follows the dashboard period. The table now shows the trial sites that started in the selected period, how many of those have since bought, and the rate, so This Week, Last 12 Weeks and Yearly each give their own figures. Products with no trial in the period are left out.
4.5.65 (production) Missing Feature Rows you can act on. Each row on the dashboard card now links to the subscription key that reported it and says how to fix it: Add feature row when the feature has no row under Product Features, or Refresh key when the row exists but the paid key was issued before it. Refreshing a key clears the rows it reported.
4.5.64 (production) Complete trial-to-paid figures. Trials registered for a personal key now count as trial sites, and a purchase converts the same customer’s trial even when they bought for a different site (matched by email). Updating fills in the history from the keys you have already issued, so Trial to paid, by product is complete straight away. Each site is counted once per product.
4.5.63 (production) See which trials become paid. When a paid key is used on a site that trialled the same product, the trial now counts as converted, dated when the key was bought. A new Trial to paid, by product table on the dashboard shows trial sites started, conversions and the all-time rate for each product. Prices beside Upgrade buttons. The tier comparison your extensions fetch now includes each tier’s price from your Payments plans, so their Upgrade buttons can say “Standard from £49/yr”. A pricing page before checkout. Upgrade buttons that name a tier now open the pricing page with that tier picked out and a Continue to checkout button, instead of going straight to the card form. Also: once you have sold a paid subscription the dashboard asks once for a review on the Joomla Extensions Directory, and the Trial keys guide link points at the guide’s new address.
4.5.62 (production) Copyright on every directory card. The extensions list now fills in a copyright the listing doesn’t have from the extension’s manifest, as each extension’s own page already did. A listing whose copyright had never been saved showed it on its page but not on its card in the list.
4.5.61 (production) Directory listings show copyright and build date for every extension. The directory now reads each extension’s copyright, author, licence and “Last Updated” date from the release ZIP it hands out, falling back to the installed extension. Previously it only read the installed extension, so a listing for an extension not installed on the site running Subscriptions Manager showed no copyright and an out-of-date “Last Updated” date. Saving a listing no longer clears a copyright that can’t be read from a manifest.
4.5.60 (production) A directory that site audits read cleanly. Download buttons are now form buttons rather than links: visitors download exactly as before, but search engine crawlers no longer follow them, so audits stop reporting download links as redirects, nofollow links and noindexed pages. The Extensions directory list now has a share image — MetaGen’s default share image, or the one Cassiopeia Themer generates. App pages get a proper page title (the app’s name and short description, with your site name as set in Global Configuration), a canonical link and share tags using the app’s feature graphic, and a single address: other routes to an app page redirect to it.
4.5.59 (production) Download links no longer loop for search engines. A Download link opened without a valid session, for example by a search engine crawler, an expired page or a shared link, now goes to the extension’s page with a note to press Download again. Previously it redirected back to itself, which site audits report as redirect loops. The extension page’s structured data also names the page as the download address rather than the download action.
4.5.58 (production) A steadier screenshot carousel. On an extension page, every screenshot now sits in the same frame, so the carousel no longer changes height between slides. Captions sit in a strip under the image, the dots that show which screenshot you’re on appear below the caption instead of on top of it, and the arrows stay centred on the image.
4.5.57 (production) One address for every directory page, and better screenshot descriptions. Each public extension page now has a single address: the extension’s own menu item if it has one, otherwise the Extensions directory with the extension named. Search engines are given that address as the canonical, share previews use it, and every link in the directory points to it. Old and alternative links (for example /component/subsmgr/?view=extension…) redirect there permanently, so no page is indexed twice. The directory list does the same and keeps any filters. Screenshots gain a Caption field, shown under the image and used as its alternative text; without a caption each image is described as, for example, “MetaGen – screenshot 2 of 4”, so no two share the same description.
4.5.56 (production) Social previews for your extension directory. The public extension pages and the directory list now publish their Open Graph tags in the form Facebook, LinkedIn and search tools read, include the page address, and give the extension image as a full web address — so shared links show a proper title, description and picture, and SEO audits no longer report the tags as missing or not matching the canonical.
4.5.55 (production) Customers on the Updates list, and email only for those who are. Registering now puts a customer straight on the Verified Forms Updates list, rather than waiting for a manual sync. A new Add customers to Updates button on the Customers page adds everyone else — including customers who bought without registering — and never re-subscribes anyone who unsubscribed. The page shows how many customers are on no list, and the Email buttons are unavailable, with the reason, for anyone on no list or unsubscribed.

Ready-written customer emails. The Email button on the Customers page and on each customer’s page now opens a complete email suited to where they stand — a check-in for paying customers, a nudge with plan links during a trial, a win-back when something has ended, or a getting-started note after a payment — naming every relevant extension, not just one.

Tidy the email history. An entry in a customer’s email history can now be deleted, for an email you opened but didn’t send.
4.5.54 (production) Hide customers from the Customers list. Each customer now has a Hide button — useful for your own sites and test accounts — so the list shows the people who matter. Nothing about the customer is changed or deleted. A Show filter switches between customers who aren’t hidden (the default), hidden customers, and everyone, and Unhide brings a customer back.

Smaller fixes. The extension picker and the Tiers list filters now fall back quietly if their data can’t be loaded, instead of showing an error.
4.5.53 (production) A Customers page. A new Customers page lists everyone with a subscription key or a payment, one row per person, paying customers first: their products and tiers, status (Paying, Paid with no key, Trial, Lapsed), what they have paid through Payments and when, when their site last checked in, their email lists in Verified Forms, and when you last emailed them. Search by name, email or domain and filter by status or product. The dashboard’s Paying Customers figure now opens it. The old worklist of renewals, upgrades and lapses is renamed Retention.

A fuller customer page. Each customer’s page now shows their current tier for each product, their payment history, their email lists and every email sent to them from the admin. It also opens for someone who has paid but has no key yet.

Know who you’ve emailed. Every Email button in Subscriptions Manager now records the email — who, when and about what — and lists show when each customer was last emailed. Retention lists, and the dashboard’s Lapsed and Expiring lists, no longer include customers who have already renewed or upgraded, so nobody is asked to buy something they already have.
4.5.52 (production) Ready-to-send win-back emails. The Email button on Lapsed but Still Running (dashboard) and on the Activity page’s expired list now opens a complete email in your mail client, not just a subject line. An expired trial is invited to subscribe — naming the site it is still installed on — and an expired paid subscription is asked to renew at its tier, each with a link to the product’s pricing page on your site. The email is signed with your name, and you can edit it before sending. Other contact emails now refer to the customer’s subscription rather than a licence.
4.5.51 (production) One period for the whole dashboard. The date range selector (This Week, Last Week, Last 12 Weeks, Yearly) now sits at the top of the dashboard as a highlighted Period bar and applies to everything below it: Analytics, the New Paid figure, and the Health lists — new paid registrations, paid but not activated, lapsed but still running, captured trial leads and missing feature rows. Each section shows which period it covers; Expiring Soon still looks ahead 14 days and says so. Your choice is remembered between visits.

Anomaly checks that age out. The Anomaly Detection page has its own remembered period — last 7, 30 or 90 days, 30 by default — for the domain-limit, rejection and invalid-key checks, so old events drop off the report. Domain-rejection bursts previously counted every validation a key had ever made rather than its recent rejections; it now counts only rejections in the period. Paid keys over their domain limit now uses the limit validation actually enforces, so Enterprise keys are never shown with a limit of one, and www. and non-www. addresses count as the same site.

Enterprise domains always unlimited. An Enterprise key upgraded from a lower tier could keep that tier’s domain limit when its product had no max_domains feature set. Enterprise now falls back to unlimited domains.
4.5.48 – 4.5.50 (production) See which product features are missing a row. When a product checks its subscription, it can now name the features it enforces. Any of those with no matching row in Product Features is recorded and listed on the dashboard under Health, by product, tier and feature, with a count of how often it was asked for — the first place to look when a customer reports a feature that won’t switch on. The product keeps working on its built-in tier defaults meanwhile, so adding the row is the fix. Recording never affects the validation answer, older products that don’t send the list are unaffected, and only the last few characters of a key are stored.

Accurate pricing in search results. The structured data on an extension’s pricing page now carries the real lowest paid price and currency and links to the pricing page, and is left out when no paid plan applies; it previously advertised a fixed placeholder price at an address that didn’t exist. The thank-you note’s support link now goes to the contact page.
4.5.47 (production) Merge duplicate extensions in the directory. A new Merge action on the Extensions list consolidates two directory records for the same extension — the kind left behind when an extension is repackaged (for example a component com_x that later ships as a package pkg_x), each carrying its own split download and hit totals. Check the source record(s), choose the target, and in one step its download and hit totals are added to the target and its download/hit history re-pointed, so the all-time, time-windowed, JED and analytics figures all stay correct; the source record is then removed. It is an admin-only maintenance action behind a clear destructive-confirmation dialog — a live summary naming exactly what will be deleted and where the totals go, and a required backup acknowledgement — and it refuses to run if a source still has subscription keys, so licence data is never stranded.
4.5.46 (production) More reliable update checks, and clearer download metrics. Subscriptions Manager now serves its update feed from a dedicated address (updates.multizone.co.uk) instead of the main website, sidestepping a security challenge that could occasionally cause a “Could not parse” error when Joomla checked for updates — applied automatically on install, and updates remain free with no key required. The public extension-directory download count now reflects first-time downloads (acquisitions) rather than update fetches, and downloads that arrived from the Joomla Extensions Directory are now tracked and shown separately once there’s a meaningful number.
4.5.35 – 4.5.45 (production) Amazon Appstore support for the app directory. A mobile app can now list an Amazon Appstore link as a first-party store, alongside Apple and Google Play — it appears with the Amazon logo in the admin app list and as a store button on the public app pages. The Source Code Licence field also gains a “See licence attribution in the app” option for apps that rely on many third-party libraries attributed in-app. Includes assorted trial and licence-handling consistency fixes from this run.
4.5.34 (production) Validations list shows the real extension name for trial check-ins. In the Validations log, anonymous trial check-ins now show the friendly extension name (for example “Content Planner”) like paid keys do, instead of a raw slug — resolving it whether the trial was logged under the component or the package name.
4.5.21 – 4.5.23 Directory and app view counts now reflect visitors, not page clicks.
  • One view per visit. Each is now counted once per visitor session, so the Directory Views figure more accurately reflects genuine visits rather than clicks — the same applies to individual extension and app detail pages.
  • Better bot filtering. The crawler filter now also excludes today’s AI/LLM crawlers and agents (and common scripted HTTP clients) that the previous list missed, so automated traffic no longer inflates view counts. Mobile-app view counts are now filtered for bots too, before the counter is touched.
  • Note: figures recorded before this update remain as they were; the improvement applies to views recorded from now on.
  • Settings tidy. The Validation Log Retention option labels now match the Default Subscription Period style (e.g. “365 days (Annual)”, “Never removed”).
4.5.20 A cleaner validation log — grouped by domain, dev noise hidden, and automatic pruning.
  • IPv6 addresses read correctly. Sites that check in from a raw IPv6 address now show the full address in the By Domain rollup instead of a truncated fragment.
  • Hide local / dev by default. The Validation Log has a new filter (on by default) that hides loopback, private-network and development check-ins — your own and testers’ installs — so the log shows real customer activity. Flip it to “Show” whenever you want the full picture.
  • Readable international domains. Internationalised (punycode) domains are shown in their normal Unicode form.
  • Automatic log retention. A new Validation Log Retention setting keeps the log from growing without bound — events older than the window (default 365 days, to match the charts) are pruned automatically. Last-seen and active-site figures are unaffected, as they’re stored on the key rather than the log.
4.5.18 – 4.5.19 A sharper admin: a subscriptions health worklist, validations grouped by domain, and actionable anomaly follow-ups.
  • Subscriptions Health worklist. The dashboard now opens with a Subscriptions Summary at the very top, followed by a Subscriptions Health section — full-width tables for new paid registrations, paid-but-not-activated, expiring soon, and lapsed-but-still-running — each row with a one-click Open and a pre-filled Email so you can act without hunting for the key.
  • Validations by domain. The Validation Log gains a By Domain rollup that groups events by their registrable domain — mail., www. and the bare host all fold into one row — showing the customer(s), extensions, total checks, result mix and last seen at a glance. Click a domain to drill into just its events.
  • Actionable anomalies. Every anomaly can now be Resolved — an audited clear that quietly reappears only if it gets worse — or answered with a pre-filled Contact email, so you clear noise without simply silencing it. A new Invalid-key probing signal flags keys that don’t exist being validated repeatedly.
  • Warmer retention queues. The Customers worklist now surfaces engaged trials and expired-but-still-running licences as contactable, one-click follow-ups for conversion and win-back.
  • Correct pricing links. The “See pricing” calls to action now point at the right extension’s premium page.
4.5.16 – 4.5.17 Pricing pages follow your site theme, plus a tidier admin layout.
  • Themed pricing. The extension pricing, premium and download cards now use your site’s own colours and buttons — and adapt to light / dark mode — instead of fixed greys and greens, so they sit naturally in any theme (including Cassiopeia Themer palettes).
  • Admin layout. Dashboard and settings content lines up flush with the toolbar and system messages for a cleaner, more consistent screen.
4.5.0 – 4.5.14 A professional “Edit your profile” page, marketing opt-in back at sign-up, dashboard polish, and a cleaner update experience.
  • Marketing opt-in at registration and profile. Signing up — and the profile page — now offers a clear, unticked “send me occasional product news” opt-in, the easiest way for customers to join the list, alongside the dashboard toggle and Verified Forms’ double opt-in. It only ever affects the marketing list, never your account emails. (Shown only where Verified Forms is installed.)
  • A coherent profile page. The member profile is rebuilt as clean, consistent cards — Account, Email Communications, Passkey Login and Multi-factor Authentication — in keeping with the rest of the site. The username is shown read-only (it can’t be changed here), and the Change password, Passkey and Multi-factor sections tuck away behind their headers so the page isn’t cluttered. Settings a customer never needs (admin language, editor, dark-mode toggle, timezone) are removed.
  • Clear, consistent consent. Privacy and email consents are now simple one-line checkboxes that line up with every other field: “I agree to the Privacy Policy” and the essential “Extension update notifications and support emails”, with optional product news below.
  • No re-ticking on every edit. Consent is asked once, at registration. When an existing customer edits their profile they aren’t made to re-agree to what they’ve already accepted — the privacy agreement isn’t shown again, and the essential-email consent shows as already on.
  • “Account settings” on the dashboard. The subscriptions dashboard now has an Account settings button next to Browse Extensions, taking customers straight to their profile page.
  • Readable dashboard prompts on every theme. The contextual cards in the dashboard header (renew, upgrade, trial, all-active) now use dark text on a soft tinted background, so they stay legible even on site templates that recolour the Bootstrap palette.
  • Quieter validation log for trial keys. Routine “valid” check-ins from trial sites are now recorded at most once per site per day, the same as paid keys — so the Validations screen shows real activity instead of pages of repeats from a single busy trial. Every non-valid result (suspended, revoked, expired) is still logged in full.
  • Update screen links back to your directory. When a customer checks Extensions → Update, each of your extensions now links to its own public page in your Subscriptions Manager directory — a fresh route back to your site (and your changelog and upgrade options) every time they update, trial users included. The old inline changelog button, which rendered an unreadable XML list, is removed in favour of that link.
4.4.0 – 4.4.1 A quieter, more readable validation log. Routine “valid” check-ins from customer sites are now recorded at most once per site per day, rather than every time an older extension calls home — so the Validations screen shows real activity instead of pages of repeats. Nothing actionable is lost: invalid, expired, suspended and domain-limit results are always logged with their reason, a site’s first check-in from a new domain is always recorded, and the “silent churn” and active-site figures are unaffected (they track the most recent check-in, not the volume). A new database index keeps the check fast on the validation endpoint.
4.3.7 – 4.3.9 Email preferences on the subscriptions dashboard.
  • Two clear rows. The dashboard’s “Email updates” card now separates Product updates (service emails about the products you own — part of your account, with no on/off switch here) from Marketing (opt in or out yourself, any time). The marketing toggle only ever affects marketing, never your product updates.
  • Resume emails If you’ve unsubscribed from all email via an unsubscribe link, the card says so rather than showing “active”, and offers a Resume emails button that brings you back — lifting the underlying suppression so mail is delivered again.
Requires Verified Forms — the card only appears where it’s installed.
4.3.0 – 4.3.6 Featured Panel — a weekly cross-sell card you edit once and every extension shows.
  • New “Featured Panel” screen. Compose a short “Featured this week” card — eyebrow, title, body, a call-to-action button and a “stay informed” link — with a live preview. Edit it once a week; there is nothing to release.
  • Shown across the whole family. Every Multizone extension’s admin dashboard “More from Multizone” panel — including Subscriptions Manager’s own dashboard — fetches the card from this site and shows it above the catalogue. This reaches trial users too — the one audience there’s otherwise no way to email — nudging them toward a subscription.
  • Per-extension review link. Each panel shows a “Leave a review on the Joomla Extensions Directory” link pointing at that extension’s own listing, taken from its Extensions Manager JED URL (set the URL on the extension’s record and the link appears).
  • Served over a public, cached API endpoint (v1/subsmgr/featured/{product_slug}); panels fail quietly to the plain catalogue if the site is unreachable, and the card is kept off the licence-validation channel by design.
  • Quieter validation log. Alongside a client-side fix shipped across the paid extensions, trial installs now re-validate about once a day instead quite frequently — so the Validations screen reflects less noise.
4.2.0 Registration consent simplified to a single clear card, self-service email preferences on the dashboard, and Marketing Subscribers retired from sign-up.
  • One clear consent card at registration. The registration page now leads with a single “Email and Privacy Policy Consent” card that folds the website privacy policy and essential account emails into one plain-English statement — sign-in and account changes, subscription confirmations and expiry reminders, extension updates and licence changes, and support replies. These are essential service emails, accepted as part of creating an account (there’s no separate checkbox to miss); marketing is kept explicitly separate and opt-in. The Register button is now a clear green call to action.
  • Self-service email preferences. When Verified Forms is also installed, the subscriptions dashboard gains an “Email updates” toggle so customers can opt in or out of product-news email themselves, any time. The toggle only ever changes the marketing list — it never affects the account access that keeps your downloads and updates available.
  • Marketing Subscribers retired from sign-up. Optional-marketing consent no longer lives on the registration and profile forms; marketing consent is now handled entirely through Verified Forms’ double opt-in and the dashboard toggle. Existing members of a marketing user group can be folded into the Verified Forms list with its “Sync from groups” action. Account-email consent (which gates downloads and updates) is set once at registration and is not part of the marketing toggle.
  • Installs cleanly on update — no uninstall/reinstall needed; the consent plugin self-heals its run order so the privacy fold works reliably.
4.1.2 Link your listings to the Joomla Extensions Directory. Each extension in your directory can now carry a “Joomla Extensions Directory URL”. When set, the public extension page shows a “Listed in the Joomla Extensions Directory” link, marked with the Joomla icon, under the extension type — giving visitors a direct route to your JED listing and reviews.
4.1.0 (production) Signing-key management, rotation and recovery without the command line; the issuing authority is now proven by key possession, not by domain; new production signing key.
  • Signing Key screen. A dedicated screen to Generate your signing key on a new install, Rotate it for routine hygiene, and run Recovery if a key is compromised — all in-product, no OpenSSL command line required. Your public key is shown in full with a copy button and fingerprint so you can embed it in the extensions you license, and the private key’s status (present / missing / mismatch) is shown without ever revealing it. New installs are guided by an onboarding prompt until a key exists.
  • Rotation that customers never feel. A rotated key is endorsed by the previous one and trusted automatically through the signed chain — client extensions adopt it on their next validation with no rebuild and no re-keying. Your customers’ subscription keys never change; only the response signature does.
  • Subscription authority by key possession. The old *.multizone.co.uk “master mode” is gone. An install now runs as the issuing authority — at enterprise, so it can create keys — only when it holds the private signing key that its released extensions trust. This is checked cryptographically on every validation and cannot be faked by editing the database, self-issuing a key, or repointing validation. A third party running their own Subscriptions Manager licenses their products with their key, and validates their Subscriptions Manager subscription normally.
  • New production signing key. This release ships a fresh signing key as a security precaution. Customer sites simply auto-update; subscription keys are unaffected.
  • Self-validation hardened. Subscriptions Manager now validates its own subscription remotely and verifies the signature exactly like the other extensions (fixing a content-negotiation error that had silently dropped it to trial).
  • Choice of private-key storage — database (default) or a file outside the web root for a stronger production posture. Rotation and recovery behave identically either way.
  • Internal: retired the bundled Multizone seeding overlay (the product is updated in place now), and added regression tests that lock the dev/prod public-key build injection, the validation request format, and the signing-key trust chain.
4.0.33 – 4.0.48

Joomla framework gate — consent plugin now goes through the User model; DB Check self-heals stuck subscription_keys.status enum; dashboard Upgrade CTAs unified.

  • Fixed Consent plugin to uses the same path Joomla’s own com_users uses, so events fire and the change is logged.
  • Fixed an issue with Joomla 5’s DB Check throwing “wrong type or attributes for column 'status'.
  • Trial Keys integrator panel. The Trial Keys list view now leads with a collapsible “About trial keys (for integrators)” card explaining what trial keys are and how third-party developers can wire them into an extension that licenses through this Subscription Manager. See the separate integration documentation.
  • Dashboard Upgrade Subscription-status alert + support_pane upgrade prompt re-synced byte-identical with all our extensions. Subsmgr’s own dashboard is the upgrade destination so it doesn’t carry the full CTA stack, but the status alert and support pane match the rest of the family.
4.0.22 – 4.0.32  Dashboard, retention tooling and analytics.
  • Dashboard rebuilt around retention and upgrades — an Analytics panel with a single date selector (This Week / Last Week / Last 12 Weeks / Yearly) driving a Views→Downloads conversion rate, trend graphs, and active subscriptions by tier.
  • Customers worklist (formerly Activity) — five action queues: renewals at risk, upsell signals, hot trials, silent churn and lapsed support, each row linking to the key or a pre-filled email.
  • Per-customer drill-down — one profile page gathering all of a customer's keys, tiers, domains and recent validation activity.
  • Metrics — rebuilt on call-home “liveness” vs “entitlement”: active counts exclude expired keys, paying customers are counted per real customer, “New Paid” replaces the always-zero “converted to paid”, and installs are split into anonymous trial sites vs emailable registered installs.
  • Domain-binding fix — the permitted-domains limit is resolved live from the tier and Enterprise keys are never wrongly blocked with “domain limit exceeded”.
4.0.21 Joomla 6 compatibility for tier sync & validation. Remote licence validation and tier-feature sync now read HTTP responses through the current Joomla API. On Joomla 6 validation and tier sync could silently fail. No configuration change required.
4.0.20

Paid-extension checkout fixes.

  • Paid extensions no longer present a “Free Trial” download button. Both the extension detail card and the pricing page now show Subscribe / Pricing calls-to-action only — free trials are offered for free and trial extensions, as intended.
  • Buying a paid extension now routes to the correct checkout. Previously the trial button dead-ended at an old checkout URL and could drop you on the Standard tier regardless of selection.
3.2.0 Joomla 6 Pre-Update Check no longer flags plg_system_subsmgrtasks or plg_system_subsmgrconsent as Potentially Dangerous Plugins. Each system plugin now declares its own compatibility-only update manifest so the check can verify J5 / J6 compatibility — pkg_subsmgr itself remains the canonical update path, so customers always update via the package.
3.1.7

Production release consolidating issues found in testing. Versions 3.1.1 through 3.1.6 iterated through the changes below before this consolidated release shipped.

Validation drill-down + traffic reduction + SEO.

  • New Validations admin view (view=validations) at Components → Subscriptions Manager → Validations. Filterable, paginated list of every validation API call from customer sites — time, domain, IP, extension, tier, customer, masked key, and result. Per-row details panel expands to show the full key, User-Agent, and pretty-printed response JSON. Filters: search (key/IP/UA), result, tier, domain, date range. Drill-down link from the Activity card's "Recent validations" section.
  • Validation traffic reduced ~one-per-page to one-per-day-per-site. Two long-standing bugs combined to make the cache useless: server signed extra fields the client didn't reconstruct (signature always failed, cache always cleared), and paid-key TTL was 15 minutes anyway. Server now signs only the canonical 8 fields with metadata appended after; paid-key TTL bumped to 24 hours, matching trial. Net effect: at most ~1 validation per active customer site per day, per extension.
  • The four shared SubscriptionValidationTrait copies (across pkg_artigen, pkg_payments, pkg_themer, com_veriform) are now byte-identical except for namespace; pre-push test gate refuses any future drift.
  • Trial validations now logged. Trial-key validations went through a separate code path that updated rollup analytics but never wrote a per-event row. The Active Sites count under-reported and the new Validations view never showed trial sites. Fixed: trial validations write to key_validation_log alongside paid validations.
  • SEO meta description per extension and per app. Both edit forms gain a Meta Description field. The site-side detail pages render it as <meta name="description"> in the page <head>, falling back to short description when empty. Same value drives the Open Graph description for social previews. Aim 150–160 characters.
  • Public download counts hidden under 100. Low numbers read negatively on a young site (“12 downloads” undersells a good extension). Threshold-gate; the per-extension show-downloads opt-out is unchanged on top of it.
  • Internal: phantom “Table 'subsmgr_validation_cache' does not exist” warning in the Joomla DB checker silenced. Pre-push test infrastructure (PHPStan + Pest + per-extension drift checks + HTTP smoke) gating pushes to main.
3.1.0 All five extensions updated to 3.1 — coordinated production release.
3.0.38–3.0.48

Dashboard rebuild.

  • KPI strip switched from rolling 7 days to the last full Monday–Sunday calendar week so numbers are stable and comparable week-over-week. Date range shown next to the heading.
  • Two wide cards replace the four old nav cards: Subscription Keys (total active + tier breakdown grid + expiring-soon warning) and Activity (directory views, downloads, trials, active sites — all for last week).
  • New Active Sites metric counts distinct customer domains that called the validation API in the period — a proxy for active customer sites.
  • New Activity admin view (view=activity) with weekly (12-week) and monthly (12-month) bar charts plus recent downloads, recent registered trial keys, and recent validation events.
  • Bot User-Agents are no longer recorded in extension_hits, extension_downloads or mobile_app_hits, so directory-view counts reflect humans rather than crawlers. Existing rows are untouched.
  • "Trials" combines unregistered trial downloads with any registered trial keys created in the period (since the public download endpoint serves trials anonymously).
  • Subscription Status card gains a small Usage panel: progress bars on capped tiers (info / warning / danger thresholds at 75% / 90%), a single muted "Unlimited on your tier" line on master.
  • Revalidate Subscription moves to a dashboard toolbar button. The standalone view=subscription admin view is removed (its content was already on the dashboard). Same toolbar button added to com_artigen, com_payments, com_themer and com_veriform.
  • Quick Actions panel removed: Send Expiring Emails, Manage Tiers, Purchase Subscription, Get Support, and the dangerous Factory Reset button are all gone. TestemailController and FactoryresetController deleted.
  • Schema cleanup (4.0.24.sql migration): drops subsmgr_validation_cache (zero references), subsmgr_download_log (model existed but never written), and subsmgr_key_usage_log (data lives in key_validation_log via SubscriptionKeyService). Dead admin views/models/controllers tied to those tables are removed too.
  • Validation logging fix: the JSON API at /api/index.php/v1/subsmgr/validate now correctly populates key_validation_log via SubscriptionKeyService::logValidation; client-side SubscriptionService::getValidationBaseUrl gains dev-host detection so .test and *.multizone.co.uk subdomains validate against the dev master rather than production.
3.0.37 Joomla 6 update XML targetplatform now includes 6.* so the Pre-Update Check no longer flags the package as J6-incompatible. Dashboard tile regex fix in the “Multizone Extensions” panel: the previous removal regex was lazy-matching the first nested </div> inside a tile, leaving the back half of <li> markup orphaned in the module content; replaced with a tempered-greedy pattern anchored to </li> so future uninstall + reinstall cycles can no longer corrupt the panel.
3.0.36 Joomla 6 compatibility for the bundled plg_system_subsmgrtasks system plugin. The legacy flat-file plugin (root-level subsmgrtasks.php with deprecated protected $app/$db properties and an empty onAfterInitialise()) was the source of the J5→J6 pre-update warning. It has been replaced with the modern namespaced Ezone\Plugin\System\Subsmgrtasks structure that was already in the source tree but never packaged: real ExpiryNotificationTask for scheduled subscription-expiry emails, service provider, PSR-4 layout. pkg_script postflight removes any orphan flat-file from existing installs.
3.0.33–3.0.35 Internal refinement of the Mobile Apps Directory shipped in 3.0.32 — admin list filters, dashboard KPI counters, security-audit dates rolled forward.
3.0.32

Mobile Apps Directory — new sibling to Joomla Extensions.

  • Admin CRUD for mobile apps with name, SKU, description, category, platforms (iOS / iPadOS / macOS / watchOS / tvOS / Android / Android TV / Wear OS / Windows), price note, development tool (Flutter, React Native, Swift, Kotlin, Java, Xamarin, Ionic, PWA, Cordova, NativeScript), source licence (BSD 3-Clause default, MIT, Apache, GPL, LGPL, MPL, Unlicense, proprietary) with plain-English explanatory notes, current version, company URLs and copyright.
  • Store links: Apple App Store, Google Play, plus a subform repeater for additional stores (Amazon Appstore, F-Droid, Microsoft Store, etc.).
  • Media: app icon, feature graphic (wide banner shown on featured directory cards), platform-tagged screenshots, and video URLs (YouTube, YouTube Shorts, Vimeo, direct MP4).
  • Site Apps Directory (view=apps) with search and platform filter. Featured apps render as full-container-width hero cards with feature graphic + store badges; non-featured apps in a responsive card grid.
  • Site app detail view (view=app): hero with icon/author/badges, official Apple/Google store badges, screenshots organised by platform in Bootstrap tabs, videos grid, technical details card, links card and publisher/copyright footer.
  • Per-event hit tracking (#__subsmgr_mobile_app_hits) with directory-landing sentinel row.
  • Dashboard "Directory Views (7 days)" KPI now shows a combined total with a Joomla Extensions / Mobile Apps breakdown row (apps row shown only when manage_mobile_apps feature is available).
  • Premium feature gate: admin management requires Premium or Enterprise (manage_mobile_apps product feature). Trial/Standard installs see the submenu but are redirected to the dashboard with an upgrade message. Public directory and already-published apps remain visible on all tiers.
3.0.30 New stable JED-compatible download URL: index.php?option=com_subsmgr&task=download.latest&extension={slug}. Free extensions serve the latest ZIP directly; trial/paid extensions redirect to the detail page where registration/login gates the download. Suitable for JED "Free" and "Free but registration required at link" listing types.
3.0.29 Per-event activity tables (#__subsmgr_extension_hits, #__subsmgr_extension_downloads) enable time-windowed analytics: new Period filter (All Time / Last 7 days / Last 30 days) on the admin extensions list scopes hits and download counts accordingly. Dashboard KPIs refreshed: "Directory Views (7 days)" (tracks the site Extensions Directory landing page) and "Downloads (7 days)" replace the single "Downloads This Month" card; the Extensions KPI is removed in favour of a focused 4-card layout. Extension edit view now reads version from the installed Joomla manifest XML on every load (no longer shows stale DB value between deploys).
3.0.28 Component renamed to “Subscriptions Manager” (plural) across language strings, manifests, documentation and JED graphics. Download count now increments on all three download paths: free-extension direct downloads, key-authenticated downloads, and the Joomla update system package endpoint. Guest download support for free extensions (keyless one-click download flow from the site detail view).
3.0.27 GDPR email consent plugin: update and marketing consent checkboxes on registration, marketing opt-out toggle on profile edit, consent-based user groups for Joomla mass mail filtering, sendEmail management, consent audit trail in privacy consents table.
3.0.26 Fixed SQL installation error on MariaDB – removed unsupported ADD COLUMN IF NOT EXISTS syntax from installer SQL that caused fresh installs to fail
3.0.25 Hit counter tracking page views per extension detail page (admin list and edit view); manifest auto-detection populates copyright, author, author email, author URL and licence type from installed Joomla manifest XML; author email updated to This email address is being protected from spambots. You need JavaScript enabled to view it. across all manifests
3.0.24 Automated security scanning added to release workflow – grep-based static analysis covers CSRF, XSS, SQL injection, input validation, information disclosure, and error handling across all extensions. Security testing card on extension detail page now shows “Tested” date in card footer. CTA subtitle output escaped for defence-in-depth.
3.0.23 Extensions directory polish: version number on its own metadata row, last-updated date display, Joomla version badges (J5, J6) parsed from compatibility data, extensions grouped by category with auto-generated headings and item counts
3.0.22 Smarter CTA cards: trial/paid extensions without payment plans now show a “Contact Us” card instead of incorrectly displaying “Free”; updated extension editor help to document all three access models
3.0.21 Unified pricing card structure: premium hero card, extensions list cards and extension detail card now share identical layout via shared PricingCardHelper; new payment trust line ("No payment required" / "Secure checkout by Stripe"); featured ribbon hidden when no label is set
3.0.17 In-component Help view with component-wide and per-view content, matching the pkg_payments pattern; help strings and view wiring updates
3.0.16 Split Stripe configuration checks into separate test/live sections in Setup Checklist for clearer visibility of which key set is configured
3.0.15 Multizone overlay refresh, data extract utility, and release notes housekeeping
3.0.14 Setup Checklist view: per-product configuration status with checklist items for extension directory and payment setup, KPI summary cards with threshold colouring, cross-component links to edit views
3.0.13 Cross-promotion panel, hide pricing button for free access model extensions
3.0.12 KPI backfill fixes, product feature filter improvements, cancel page tag corrections, safe multizone uninstall
3.0.11 Extension detail view redesign: pricing card matches list view pattern, tier comparison highlights featured tier, screenshots in full-width carousel, Requirements and Compatibility side-by-side, Documentation/Version History/Demo buttons in hero, Details button on premium view
3.0.10 Extensions list CTA card redesign with access model pattern, carousel chevron and indicator styling fixes, public changelogs for all extensions
3.0.9 Extensions directory redesign: responsive hero card replacing banner image, CTA pricing cards with trial days and download buttons, Bootstrap carousel with styled chevrons and indicators, consistent card widths, back link SEF URL fix, "Joomla Type" moved to extension info
3.0.8 Extension directory cards enriched with icons, category and licence badges, screenshot carousel, and copyright auto-detection from manifests
3.0.7 Featured tier pricing cards on extension detail view, payments plan unique key constraint fix
3.0.6 Publication changelogs for all extensions, SQL migration sync in postflight
3.0.5 Subscription widget link corrections, terminology alignment, grouped dashboard tile format migration and sizing fixes
3.0.4 Whole-number pricing display, Stripe tax label support, plans Stripe column additions
3.0.3 Active subscribers KPI, checkout improvements, success page account details
3.0.2 Bootstrap text-bg-* colour treatment across all site templates for theme compatibility
3.0.1 Dashboard house style standardisation, tier limits and pricing alignment across all products, grouped Home Dashboard tile
3.0.0 Major dashboard redesign with KPI cards, navigation cards, support pane, compact subscription status, and simplified tier limits
2.9.9 Bootstrap text-bg-* colour treatment across all site templates (premium, error, extension, extensions, dashboard) for theme compatibility
2.9.8 Per-row CTA buttons (Upgrade/Renew) for each subscription key, download button always visible
2.9.7 Theme compatibility fix for dashboard CTA card colours using Bootstrap 5.2+ text-bg-* utilities
2.9.6 Contextual CTA hero card on dashboard, domain usage column, streamlined subscription table with plural-aware headings
2.9.4 Tier comparison table on premium view, dev/prod URL isolation, multizone overlay manifest fix
2.9.2 Consolidated downloads into component admin folder, auto-detect version from download artifacts
2.9.1 Simplified download system with database-driven resolution, removed config-based URLs
2.9.0 Block unpublished extensions from direct URL, JED Checker compliance, idempotent multizone overlay
2.8.10 Fix in Extensions HtmlView
2.8.9 Removed internal tooling
2.8.8 JED Checker compliance: GPL licence fixes, deprecated API migration, language file deduplication
2.8.7 Mutually exclusive contact method fix, menu item param lookup for per-extension contact settings
2.8.6 Contact call to action for paid extensions, premium view contact scenario, and security hardening
2.8.5 Contact fixes
2.8.4 Theme compatibility refinements
2.8.3 Cassiopeia theme compatibility, contact conversion scenario
2.8.2 Security hardening across component
2.8.1 Product feature limit enforcement, branding updates
2.8.0 Site view restyling, extension directory with URL slugs, dashboard improvements
2.7.0 Product Features system, master mode validation, multizone data separation
2.6 Admin interface improvements and workflow refinements
2.5 Subscription key management enhancements
2.4 Email notification improvements and logging updates
2.3 Tier system refinements and performance optimisation
2.2 Extension directory and frontend improvements
2.1 Stripe payment integration via com_payments
1.0 Initial release — subscription key management with tiered system

Licences, trademarks, source code licences and attributions

928uk® is a trademark of Multizone Limited, registered in the UK. Multizone and this site is not affiliated with or endorsed by The Joomla! Project™. Any products and services provided through this site are not supported or warrantied by The Joomla! Project or Open Source Matters, Inc. Use of the Joomla!® name, symbol, logo and related trademarks is permitted under a limited licence granted by Open Source Matters, Inc. AdMob™, AdSense™, AdWords™, Android™, Chrome OS™, Chromebook™, Chrome™, DART™, Flutter™, Firebase™, Firestore™, Fuchsia™, Gmail™, Google Maps™, Google Pixel™, Google Play™, Pixelbook Go™, and Pixel™ and other trademarks listed at the Google Brand Resource center are trademarks of Google LLC and this site is not endorsed by or affiliated with Google in any way. Apple and the Apple logo are trademarks of Apple Inc., registered in the U.S. and other countries. App Store is a service mark of Apple Inc. The OSI logo trademark is the trademark of Open Source Initiative. Any other product or company names may be trademarks™ or registered® trademarks of their respective holders. Use of these trademarks in articles here does not apply affiliation or endorsement by any of them.

Where the source code is published here on multizone.co.uk or on our GitHub by Angus Fox, Multizone Limited it is licenced according to the open source practice for the project concerned.

BSD 3-Clause "New" or "Revised" Licence
Original source code for mobile apps are licenced using the same licence as the one used by "The Flutter Authors". This Licence, the BSD 3-Clause "New" or "Revised" Licence (bsd-3-clause) is a permissive licence with a clause that prohibits others from using the name of the project or its contributors to promote derived products without written consent.
GNU General Public Licence v3.0 or later
Original source code for Joomla! published here on multizone.co.uk by Angus Fox, Multizone Limited is licenced using the GNU General Public Licence. This Licence, the GNU General Public Licence Version 3 or later (gpl-3.0+) is the most widely used free software licence and has a strong copyleft requirement. When distributing derived works, the source code of the work must be made available under the same licence.

Please respect the licences and dont use the name of this site or our company to promote derived products without written consent. I mean, why would you? You're not us!

Amazon Associate
As an Amazon Associate we earn from qualifying purchases.
Logo
Our Logo Image is by Magnific. We chose it because its an M and also the letter A twice - and that represents us.
Graphics
Our images representing user experience and interface design are from Magnific here and here and here and here and here.