← Back to all sparks
A

AcyMailing

MKT AUTO
Velocity5.0

Email marketing and newsletter platform for WordPress and Joomla

AcyMailing spent 11.0 on a security rewrite and is now paying down the regressions.

email marketingsecurity hardeninggdprregression fixeswordpress
Current state
Patch releases arriving every few days since the 11.0.0 major. The 11.0.x line is dominated by fixes to what the rewrite disturbed — automation conditions, campaign send settings, custom field handling, add-on integrations — with small improvements alongside, such as REST API errors when a campaign targets disallowed lists and faster module insertion in emails.
Where it's heading
The arc is consolidation, not expansion. 11.0.0 reworked the codebase for security and added GDPR-aware pixel tracking; 10.11.1 before it patched a SQL injection. Since then the work has been stabilizing that base, and the attachment fix in 11.0.3 even asks administrators to re-upload files or correct permissions.
Prediction
Expect continued 11.0.x patches closing regressions from the rewrite before any new feature work resumes.

Recent moves

  1. 8d ago

    REST API error messages and faster module insertion

    More rewrite cleanup, with two real gains: the REST API now explains itself when a campaign targets disallowed lists, and module insertion got faster. The attachment fix needs administrator action.

  2. 13d ago

    Automation and multilingual campaign fixes

    A pure bug-fix patch on automations, followups, and multilingual campaigns.

  3. 14d ago

    Consent shown in form preview; translation file restored

    Tracking consent becomes visible in the subscription form preview and the pot file returns for custom translations, alongside PHP errors that were blocking page loads.

  4. 20d ago

    GDPR pixel-tracking option and a full security rework

    The major release behind the current patch run: a full codebase security rework plus a GDPR-aware pixel tracking option, with fixes for silently blocked transactional WordPress mail.

  5. 1mo ago

    SQL injection vulnerability patched

    A SQL injection patch with an explicit recommendation to update — the security thread that runs into the 11.0 rewrite.

  6. 1mo ago

    Optional IP collection and configurable statistics delay

    Privacy controls arrive as options: IP collection can be switched off at subscription, and statistics recording can be delayed.