What’s new in FileDeck — the features, improvements and fixes we ship, newest first.
Releases go out as soon as they’re ready — sometimes several in a day, sometimes a quiet week. Every entry below shipped to production.
Grant access to a team, not one person at a time
Assigning documents person by person works until it doesn't. An agency running forty client areas ends up picking the same six people over and over, and one staff change means editing every category and document that person could reach.
Groups
Documents → Groups → Add group. Name it, tick the members, publish.
Then give the group whatever it needs: tick it on a category to make that client area theirs, or tick it on a single document under Visibility → *Specific people only*.
Change the membership once and every grant follows. Remove someone from the group and they lose access to every area and document it was given, immediately. Add someone and they gain all of it.
Groups sit alongside the people you name individually and any email-domain rule on the same category — a person gets in by matching any one of the three. Adding a group never revokes anyone you had already named.
Deleting a user removes them from every group. Deleting a group removes the grants it held, so nothing is left pointing at it.
Fixes & improvements
- A document shared with a group now appears in that member's library, not only on its own page. The library query kept its own copy of the "documents assigned to me" rule, and the two copies had to be collapsed into one before groups could work everywhere — a member could previously open a document the library reported did not exist.
Match my theme now finds the colour your site actually uses
“Match my theme” inherits your theme's colours so a library looks like part of your site. It already refused to use a colour too faint to read — but when that happened it fell all the way back to your text colour, which on a light site means a black-and-white library. Technically readable, and not what anyone turned the setting on for.
It tries your second brand colour first
Most themes publish more than one brand colour. If the first is a pale tint — common on themes where the “accent” slot holds a background wash rather than a button colour — FileDeck now tries the next one in your palette before giving up on colour entirely. Only if that is also unreadable does it use your text colour.
Nothing to configure: turn on Match my theme under Settings → Display and it happens. An accent colour you have set yourself is still left exactly as you set it.
Give a whole company access at once, and show people what they already have
Two additions to client portals: admit an organisation by its email domain, and let people see their own download history.
Client areas by email domain
Naming everyone at a client company one by one meant editing the category every time someone joined or left. Now you can add a single entry:
“ @acme.example “
Anyone signed in with an address at that domain reaches the area. Mix it with named people freely — @acme.example, jrivera, contractor@other.example reads as "everyone at Acme, plus Jordan, plus that one contractor". Named people and domains are an or: adding a domain rule never revokes anyone you named.
It is stored as a rule and checked on every request, so someone who creates an account at that domain next month gets in without anyone touching the category. People admitted this way are emailed on publish like everyone else.
Worth knowing: this is only as strong as your signup process. If anyone can register with any address and change it unverified, a domain rule is not a strong control — the knowledge-base article says so plainly and suggests when to name people individually instead.
Personal download history
“ [filedeck_my_downloads] “
Every signed-in person sees what they have already downloaded, newest first, still linked so they can get it again. It pairs with [filedeck_my_documents]: one answers "what is available to me", the other "what have I already got".
Downloads only — not views, not searches. A document downloaded several times shows once. Anything the person has since lost access to drops out of the list rather than sitting there naming a file they can no longer open. And with activity logging switched off it says so, rather than showing an empty list that would read as "you have downloaded nothing".
Fixes & improvements
- The activity log gained an index on the user column, so a personal download history stays fast on a busy library.
A link that works once, and a stop to other sites spending your bandwidth
Two more ways to control how files leave your site.
Single-use download links
Open a document, choose Create a single-use link, and you get a URL that works for exactly one download and then stops. It is for handing one document to one person — a contract, a report, something you would rather not see forwarded around an organisation. The recipient needs no account, and the link expires after 7 days if nobody uses it.
The link is shown once, so copy it before leaving the screen. Leaving a live one-shot link sitting on an edit screen rather defeats the point.
The use is only spent when the download actually succeeds. If the request is turned away first — by a download quota, by IP rules, or by the refusal of automated clients on a metered document — the link is untouched and your recipient can still use it. And two simultaneous clicks cannot both win.
Hotlink protection
Switch it on to refuse downloads requested from other sites' pages, so nobody else embeds your files and leaves you the bandwidth bill.
The exceptions matter more than the rule. A request with no referrer is allowed — pasted URLs, bookmarks and most email clients send none, and refusing those would break ordinary use to prevent nothing. Signed share links are always exempt, so a forwarded link still works when the recipient clicks it out of webmail. If you syndicate downloads to a partner site, a filter allows its host.
Fixes & improvements
- Housekeeping now clears the records behind spent single-use links once the links they refer to have expired anyway.
Keep files on your network, and tell people when a document is theirs
Two gaps closed this week, both in how documents reach the right people: you can now restrict downloads to your own networks, and assigning a document to someone actually tells them.
IP rules
Restrict downloads to the networks you choose. Pick only these addresses may download for an allowlist — your office, a VPN, a customer's range — or block these addresses to shut off a specific source. IPv4, IPv6 and CIDR ranges all work, one per line.
The rules apply to every download, including signed share links. That is deliberate: an allowlist means "only these networks may fetch our files", and if forwarding a link got around it the control would be decorative.
Two things that stop it biting you: site administrators are never blocked, so a typo can't lock you out of your own library, and an allowlist with nothing in it is treated as off rather than as "refuse everyone".
Find it under Documents → Settings → Downloads.
Assigning a document now emails the person
Assigning a document to named people has been available since the summer, but it sent them nothing — the document simply appeared, and only if they thought to look. Now the people you name get an email with a link to it, the same one client areas have always sent when a document is published into them.
It only sends once per person per document, so re-saving a document never re-mails its assignees, and publishing a document that was assigned while it was still a draft notifies them at the moment it goes live rather than silently. Take someone off and add them back and they are told again.
Fixes & improvements
- Saving settings from the free edition no longer risks clearing an IP rule list configured under Pro.
Your library now matches far more themes — and stays readable
“Match my theme” is the setting that makes a FileDeck library look like it belongs on your site rather than bolted onto it. It used to work properly only on block themes. Now it reads the colours from most of the popular themes and builders too — and it checks its own work before applying them.
It knows many more themes
Turn on Match my theme under Settings → Display and FileDeck picks up the colours you have already chosen in Astra, Kadence, GeneratePress, OceanWP, Blocksy, Neve, Lightning, Sydney or Elementor, alongside the block themes it already understood. There is nothing to configure and no colour to copy across: if you restyle your site later, the library follows.
It refuses to give you an unreadable library
Some themes name a soft, decorative colour “accent” — a pale beige, a pastel, a bright lime. Those look right as a background wash and are impossible to read as a button. Previously FileDeck took the theme at its word and you got buttons you could barely see.
Now it measures the inherited colour against your page background first. If the result would be hard to read, it uses your theme's own text colour instead, which keeps the library looking native while staying legible. If you have set an accent colour yourself, that is always respected and never second-guessed.
Fixes & improvements
- On Twenty Twenty-Three and Twenty Twenty-Four, “Match my theme” produced buttons with too little contrast to read. They now fall back to your theme's text colour.
- On Twenty Twenty-Five, “Match my theme” ignored the theme's accent colours and used the default FileDeck blue instead.
The download form now works with a screen reader
If you use lead capture, the "enter your details to download" box asked for a name and an email using placeholder text alone. Placeholders disappear the moment someone types, and screen readers do not reliably announce them — so the form was hard to complete without sight, on the one step between a visitor and your file.
Both fields now have real labels and autofill hints, so a browser can fill them in and a screen reader announces what each one is for. The box itself — and the document preview box — now identify themselves as dialogs and say what they are called.
Nothing changed about how the form looks, what it collects, or how it submits.
Ask this library now works with Fireworks AI
"Ask this library" and the AI summary & tag suggestions can now run on Fireworks AI, alongside Anthropic and OpenAI. It is the same deal as the other two: your own key, your own account, and you can switch provider whenever you like without rebuilding anything.
Why you might want it
Fireworks serves open-weight models — Qwen, DeepSeek, gpt-oss and others — which are typically a good deal cheaper per answer than the big proprietary models, and fast. If you are answering a lot of questions over a large library, or you would rather your text went to an open model than a frontier one, it is now a setting rather than a wait.
Setting it up
Go to Documents → Settings → Ask AI, choose Fireworks AI as the chat provider, and paste your key. Leave Model blank to use the default (gpt-oss-120b), or name any Fireworks model you prefer — their ids look like accounts/fireworks/models/gpt-oss-120b, and if you paste just the short id FileDeck adds the prefix for you.
Your embedding provider is a separate setting and is unchanged, so switching the chat provider does not touch your search index.
Revision history, working custom order, and a clearer message if you install twice
A small follow-up to this morning's release.
Document revision history
Documents now keep revision history, the same as posts and pages. If you or a colleague overwrite a document's description, the previous version is there in the editor to restore. Nothing to switch on.
"Custom order" actually orders things
Documents → Settings → Library has offered *Custom order* as a sort option for a while, but there was no way to set an order, so choosing it did nothing. Documents now have an Order field in the editor sidebar, and that sort works as it reads.
If you had Custom order selected and wondered why your library looked alphabetical, that is why.
Fixes & improvements
- Installing a second copy of FileDeck alongside the first — most often the Pro download added as its own folder while the free version is still active — used to fail with WordPress's "plugin could not be activated because it triggered a fatal error", which tells you nothing. FileDeck now stands down cleanly and tells you which copy is running and which one to remove.
Download allowances, activity log and imports get more precise
Four things behave differently in ways you may have configured, so they are worth two minutes before you update — download allowances, what bots can fetch, how the activity log labels events, and what an import does with unpublished items.
Download allowances are counted per person
If you set a daily download allowance per role, that allowance now applies to signed-in visitors and is counted against the person rather than the connection they arrive on. Colleagues sharing one office connection each get their own allowance.
Worth checking: open Documents → Settings → Downloads and look at the numbers you have configured. Some per-role allowances may not have been taking effect, so people who were never refused a download before may start meeting a limit you set some time ago.
Metered documents are no longer served to bots
If a document has a download limit, or your site has download allowances configured, automated clients — search engine crawlers, link previews, uptime monitors — are no longer served the file. They get a polite refusal instead.
This exists so an automated client cannot quietly spend a limited document's allowance before any of your visitors get to it. People are unaffected, and documents with no limit are served to crawlers exactly as before.
The activity log is more precise about what happened
Two changes. Where the person was signed in, the log now names them instead of recording an anonymous visit — so "who" is answerable for downloads, terms acceptances and acknowledgements.
And several kinds of event that were previously filed as downloads now appear as themselves: acknowledgements, transmittals, retention rules being applied, and access reviews. If you keep period reports, expect download totals to come out slightly lower and these event types to appear alongside them. The activity did not change — only how it is labelled.
Imports no longer publish what the old plugin was hiding
Importing from another document plugin used to publish everything it found. Where the source plugin stores its documents as posts, anything it was keeping out of public view — draft, pending or private — now arrives as a FileDeck draft, waiting in the Documents list. Published items still come across published, so a normal migration looks as it did before.
After your next import, filter the Documents list by Drafts to see what was being held back, and publish what you want live.
Fixes & improvements
- A watermarked PDF now carries the downloader's email address when they are signed in, as it was always meant to, rather than reading "a visitor" on every copy.
- A category password containing symbols such as
%or<is stored exactly as you type it. If you set a category password that never accepted the password you chose, re-save it. - Starting a PDF accessibility scan completes in the background and fills in the report.
- Uninstalling FileDeck leaves a short note in the protected-files folder explaining what is in there and how to get it back. Those files stay protected — removing the plugin does not make restricted documents publicly downloadable — and nothing is deleted.
- "Delete all data on uninstall" now covers transmittal records and smart collections too, and uninstalling clears FileDeck's scheduled background tasks either way.
- Security and reliability improvements across document access, imports and outbound email.
Filters open over the library, not inside it
Opening a category or tag filter pushed the entire document table down the page by the height of the panel, and pushed it back up again when you closed it. On a library with a lot of categories that was a substantial jump, and it happened every single time somebody used a filter.
The panel now opens over the library. Nothing moves. It also closes when you click anywhere else or press Escape, which it did not do before — previously you had to click the control a second time.
This applies wherever the filters are: in the bar above the library, and in the row under the column headings.
On a browser old enough not to support overlay panels, the filters behave as they did before rather than breaking — they open in place, and everything still works.
The free version now says what Pro adds
FileDeck's premium features aren't switched off in the free version — they aren't there at all. The Visibility control simply isn't on the document screen. The Search Index tab simply isn't in Settings. Which meant that if you were using the free plugin, nothing ever told you any of it existed.
That was our mistake, not a policy. The free version now mentions what the paid tiers add, at the point where it's relevant to what you're doing.
Where it shows up
- On a document — the Visibility control appears, disabled, showing exactly the options Pro would give you: logged-in only, author only, or assigned to specific named people.
- In Settings — the sections the paid tiers add are listed under the tabs, so you can see what's there.
- On the Documents screen — if another document plugin on the same site is holding files, it says how many and that Pro can import them.
- Once a library passes a few hundred documents — a note that Pro reads the text inside your files, not just their titles.
What it deliberately doesn't do
Nothing that worked before has been locked, removed or limited. Nothing blocks you, nothing is modal, and nothing appears on activation or on a timer. Every notice can be dismissed for good, and stays dismissed. If you're on a paid plan you'll never see any of it.
We say on the pricing page that the free version has no artificial limits. That is still true, and this release doesn't touch it — the point is only that you should be able to find out what the paid version does without leaving WordPress to go and read a website.
Fixes to the new access features
Six fixes to the document-assignment and bulk-access features that shipped earlier today. One of them needs a moment of your attention.
If you used the new bulk access actions, please re-apply them
Selecting documents on the Documents list and choosing Access: logged-in users only changed their visibility — libraries stopped showing them — but did not move their files into the protected vault. The documents were hidden; the files behind them were still reachable by anyone with the direct URL.
That is fixed. If you used that bulk action today, select those documents and apply it again (or open and re-save any one of them) and their files will be protected properly. Documents restricted the ordinary way, by editing a document or a category, were never affected.
The rest
- A document assigned to specific people is now visible to administrators in libraries, as the documentation says it should be. It was being hidden from them as well, which left no way to see what you had handed out.
- The list of people on a document now always includes everyone already assigned, however many users your site has. On sites with more than 200 users, re-saving a document could previously drop an assignee who was not shown in the list — even if you only came to fix a typo in the title.
- The people picker is now only shown to users who are allowed to list site users, and email addresses are hidden from anyone who is not.
- Deleting a user, or removing them from a site, now clears their document assignments.
- Download all on a folder now downloads what you can see. If a search or filter is narrowing the folder to a few documents, you get those, not the whole folder.
Give a document to one person
Until now access was decided by role or by category: everyone with the role saw the file, or nobody did. That works for a policy library and not at all for a client portal, where the whole point is that this contract belongs to *this* client. Documents can now be assigned to named people.
Only they can see it — and only they know it exists
Set a document's visibility to Specific people only and pick the people. They can see and download it; nobody else can.
The part that matters for a client portal is what everyone *else* sees: nothing. The document does not appear in another person's library as a locked row, or a greyed row, or a title they cannot open. It is simply not there. A locked row is fine for a staff handbook — it tells you to log in — but in a portal it would tell every client the names of every other client's files.
Administrators still see everything, and assigning nobody hides a document from everybody rather than from nobody.
Download a whole folder
Folders now carry a Download all button that zips everything inside them in one go — useful the moment a client area holds more than a handful of files. It goes through exactly the same checks as any other download, so if you have lead capture, terms acceptance or bot protection switched on, they all still apply.
Fixes & improvements
- The Documents list gained bulk access actions: select any number of documents and make them public or logged-in-only in one go. WordPress already handles bulk category, tag and status changes; this covers the one thing it cannot reach, which is FileDeck's own access settings — the difference between reorganising a 3,000-document import and re-editing it.
Libraries that load after the page now work
If something on your site adds a document library *after* the page has finished loading — a page builder's tab or popup, an accordion, your own scripting — that library used to render perfectly and then do nothing. Search typed into it did not filter, the filters did not open, the column headers did not sort. Nothing appeared broken, so there was nothing to go on.
Why it happened, and what changed
FileDeck used to wire up every library once, at the moment the page finished loading. Anything that arrived later missed that moment and was never wired up at all. Libraries now announce themselves as they appear, and anything that adds one can start it.
If you build sites and want to trigger it yourself, window.filedeckInit() starts any library on the page that isn't already running, and each one fires a fdk:ready event as it starts. It's safe to call whenever you like — a library that's already running is left alone.
Nothing changes for a library placed the normal way, with the block, the shortcode or a builder widget on the page itself.