Thank you for seamlessly supporting and trusting in Mageplaza. It’s our big honor to serve you on our store. We are striving every day to bring you better service and products.
In August 2026, we released 8 updated extension(s). Please read the following information to learn what we’ve worked on this month.
Website Support
& Maintenance Services
Make sure your store is not only in good shape but also thriving with a professional team yet at an affordable price.
Get Started
8 Update(s) in August 2026
Date: 2026-08-11
Release notes:
Standard:
- Security: Fixed XSS vulnerabilities where unescaped guest names (comment author, customer name) could execute in the admin comment grid.
- Security: Enforced vote permission server-side and hardened the Like/Dislike counter against tampering.
- Security: Enforced
customer_approve on author self-registration so unapproved accounts can no longer bypass the check.
- Security: Fixed an authorization gap that let an author delete a post they didn't own.
- New Update: Added a dedicated blog search results page along with a search suggestion/autocomplete dropdown.
- Bug Fix: Fixed several category handling issues: cycles in the category tree, a missing position row, the post view page showing every assigned category instead of only the top-priority one, and a null parent ID error.
- Bug Fix: Fixed several minor issues: the post URL falling back incorrectly when the author's
url_key is empty, the module entry point returning a 404 page when disabled, a null month_key error in the archive breadcrumb, and validation of the "Blogs per Page" configuration value.
- Bug Fix: Fixed the admin comment grid's data source mismatch, the blog color picker not working with Hyvä theme, and decrypting a non-encrypted value producing invalid binary output instead of a clean error.
- Compatibility: Compatible with Magento 2.4.9 and PHP 8.5.
Professional:
- Security: Hardened the Like/Dislike counter against tampering (same fix as Standard).
- New Update: Added a dedicated blog search results page along with a search suggestion/autocomplete dropdown.
- Bug Fix: Fixed the leftbar Like button so a click always registers through the real vote action instead of a decorative handler.
- Bug Fix: Fixed a server error that occurred when saving a comment on a post that no longer exists; it now returns a clean error message.
- Bug Fix: Fixed an incorrect logo path in the article snippet template.
- Compatibility: Compatible with Magento 2.4.9 and PHP 8.5.
Read full release notes
Date: 2026-08-11
Release notes:
Standard:
- Security: Fixed XSS vulnerabilities where unescaped guest names (comment author, customer name) could execute in the admin comment grid.
- Security: Enforced vote permission server-side and hardened the Like/Dislike counter against tampering.
- Security: Enforced
customer_approve on author self-registration so unapproved accounts can no longer bypass the check.
- Security: Fixed an authorization gap that let an author delete a post they didn't own.
- New Update: Added a dedicated blog search results page along with a search suggestion/autocomplete dropdown.
- Bug Fix: Fixed several category handling issues: cycles in the category tree, a missing position row, the post view page showing every assigned category instead of only the top-priority one, and a null parent ID error.
- Bug Fix: Fixed several minor issues: the post URL falling back incorrectly when the author's
url_key is empty, the module entry point returning a 404 page when disabled, a null month_key error in the archive breadcrumb, and validation of the "Blogs per Page" configuration value.
- Bug Fix: Fixed the admin comment grid's data source mismatch, the blog color picker not working with Hyvä theme, and decrypting a non-encrypted value producing invalid binary output instead of a clean error.
- Compatibility: Compatible with Magento 2.4.9 and PHP 8.5.
Professional:
- Security: Hardened the Like/Dislike counter against tampering (same fix as Standard).
- New Update: Added a dedicated blog search results page along with a search suggestion/autocomplete dropdown.
- Bug Fix: Fixed the leftbar Like button so a click always registers through the real vote action instead of a decorative handler.
- Bug Fix: Fixed a server error that occurred when saving a comment on a post that no longer exists; it now returns a clean error message.
- Bug Fix: Fixed an incorrect logo path in the article snippet template.
- Compatibility: Compatible with Magento 2.4.9 and PHP 8.5.
Read full release notes
Date: 2026-08-05
Release notes:
- New Update: We added performance optimizations for the Abandoned Cart Board, including new database indexes to speed up report queries
- Bug Fix: We fixed a PHP 8.1+ deprecation warning caused by passing a null value to the DateTime constructor when loading the Cart Board without a date range filter
Read full release notes
Date: 2026-08-10
Release notes:
- New Feature: We added server-side GA4 purchase and refund tracking via the GA4 Measurement Protocol, running alongside client-side tracking with automatic deduplication by transaction ID, plus an admin event log grid and a Test Connection action.
- Compatibility: The extension is now compatible with Hyva 1.5, including a CSP-safe consent popup and add-to-cart event tracking.
- Compatibility: Compatible with Magento 2.4.9 and PHP 8.5.8.
- Security: Fixed a cross-store PII leak in customer data enrichment caused by a missing store filter.
- Security: Fixed 25 XSS findings across Google Tag Manager templates.
- Bug Fix: Fixed race conditions in server-side purchase capture and event reconciliation that could cause duplicate or missed events.
- Bug Fix: Fixed an issue where a cart or order item with an empty attribute set could trigger an error.
Read full release notes
Date: 2026-08-11
Release notes:
- Security: Hardened the admin log preview iframe with a sandbox attribute
- Bug Fix: Fixed multipart email body loss in SMTP transport
- Compatibility: The extension is now compatible with PHP 8.5
Read full release notes
Date: 2026-08-05
Release notes:
- Bug Fix: We fixed an issue where the popup did not show on the homepage.
- Bug Fix: We fixed an issue where the popup did not scale correctly on mobile devices.
- Bug Fix: We fixed a build error that prevented
npm run build from running with Tailwind CSS version ^4.1.
Read full release notes
Date: 2026-08-05
Release notes:
- New Update: We added the missing translation entries so every label can now be translated.
- Compatibility: The extension is now compatible with PHP 8.5.
Read full release notes
Date: 2026-08-11
Release notes:
- Compatibility: Compatible with Magento 2.4.9 and PHP 8.5
- Bug Fix: We fixed an issue where the product attribute label was registered as a translation object instead of a plain string during setup, which could store an unreadable label.
- Bug Fix: We added the missing translation entries so all extension phrases can be translated.
Read full release notes
Let’s look forward to our upcoming projects in September 2026.
Feel free to ask us questions via the chatbox. If you have technical issues, search for solutions or submit a ticket here.