Changelog

What’s new in FileDeck — the features, improvements and fixes we ship, newest first.

Releases go out as soon as they’re ready — sometimes several in a day, sometimes a quiet week. Every entry below shipped to production.

v2.55.2

Existing client uploads are repaired automatically

A follow-up to the previous release for sites that accept documents through front-end submission or client areas.

Fixes & improvements

  • Security and reliability improvements for front-end submissions: documents submitted before the previous release are now repaired automatically shortly after updating, rather than only when each one is next saved. Nothing to do — it runs once on its own.
v2.55.1

Security and reliability improvements for client uploads

An update for sites that accept documents through front-end submission or client areas.

Fixes & improvements

  • Security and reliability improvements for front-end submissions. If your site accepts client uploads, updating is recommended.
v2.55.0

Download gates now work on single document pages

If you require visitors to accept terms, complete a form, or pass a bot check before downloading, that step now appears on single document pages too.

Fixes & improvements

  • With the terms gate, form gate or bot protection switched on, the Download button on an individual document's own page previously had no way to present the acceptance step, so the download could not be completed from that page. All three gates now show the same step there that they already showed in a document library. Lead capture was unaffected.
v2.54.1

Standalone search now works everywhere

A small fix for the [filedeck_search] search box.

Fixes & improvements

  • Searching from a [filedeck_search] box on a site using plain permalinks now lands on your library with the results, instead of on the homepage. Sites with pretty permalinks were unaffected.
v2.54.0

The Popular Documents block

A small block with an outsized use: put your most-downloaded documents on any page.

Popular Documents, anywhere

The Top Downloads and Recent Documents lists have lived in sidebar widgets since they shipped. Now the same compact, access-aware list is a proper block — drop Popular Documents into any page or template, choose most downloaded or newest, cap the count, limit it to a category, and optionally show download counts.

It's built for resource-hub landing pages: a "Most downloaded" strip next to your library, powered by the download counting FileDeck already does. Like the widgets, it goes through FileDeck's access rules — a restricted document never appears in the list for someone who cannot open it.

Fixes & improvements

  • The block preview in the editor explains itself when no documents match, instead of rendering blank.
v2.53.0

Know what visitors want — search analytics everywhere, and helpful votes

Two Pro upgrades that turn your library from a shelf into a feedback loop: every search now tells you something, and every document page can ask one useful question.

Search analytics now cover every search box

FileDeck already reported popular searches and content gaps — searches that found nothing. Until now, only full-text content search fed those reports. From this release, every search surface counts: the library's own search box (including large libraries in server mode), the site-wide ⌘K command palette, full-text search, and AI semantic search all flow into the same popular-searches and content-gap reports. Known crawlers are filtered out, and a run of keystrokes counts as one search rather than ten.

The Analytics screen also gains a Searches with no results table — the documents people wanted and didn't get, at a glance, next to your top searches. The full content-gap report (with one-click "create a document from this gap") stays on the Activity log screen.

“Was this document helpful?”

Turn on Document feedback (Settings → Features) and single document pages ask one question under the download button: *Was this document helpful?* — one-click Yes/No, anonymous by design. No name, email or address is stored; just two counters per document.

The Analytics screen shows the results least helpful first, with Yes/No counts and a helpful percentage — so an outdated manual or a mislabeled form tells on itself before it costs anyone time. It's off by default: updating never changes your pages until you say so.

Fixes & improvements

  • Search logging ignores known crawlers on every surface, keeping the popular-searches report about people, not bots.
  • Repeat feedback votes from the same visitor are acknowledged politely and counted once.
v2.52.0

A smarter setup wizard

The first-run setup wizard has caught up with everything FileDeck can do now — it gets your documents in faster, and it knows what plan you're on.

Switching from another plugin? The wizard notices

If FileDeck Pro detects importable documents from another document or download plugin on your site, the wizard's last step now says so — with the plugin's name and how many items it found — and takes you straight to the one-click migration tool. Your existing plugin and its data are left untouched.

Get your files in, fast

The final step now leads with the drag-and-drop uploader: drop in a folder's worth of files and each one becomes a document. Adding a single document, or loading the removable sample library, are one click away as before — and the wizard's Finish button now lands you on your live library page, so the first thing you see is your library working.

Your plan's next steps, built in

On Pro sites the wizard ends with a short "worth setting up next" list — building the content search index, restricting categories, connecting cloud storage — and on the AI & Governance plan it also points you at choosing an AI provider and adding your key, since AI features stay off until you do.

Fixes & improvements

  • Loading the sample library from the wizard now counts as finishing setup, so the "finish setting up FileDeck" reminder no longer appears afterwards.
  • Every path out of the wizard (including adding your first document) now completes it — previously some routes left the setup reminder showing.
  • The opt-in weekly usage ping now also reports how the setup wizard ended and whether the sample library was used — still anonymous, still sent only if you opted in to usage tracking.
v2.50.0

A hardening pass across the Pro features

A maintenance release. Hardening across the Pro feature set, with no change to how anything works day to day.

One note if you run multisite

Download links signed before this release need re-issuing, including any sent by transmittal. Single-site installs are unaffected — existing links keep working exactly as before.

Also in this release

  • A document refused because it has hit its download limit is now recorded in the activity log, so you see it rather than hearing about it from someone who couldn't get the file.
  • Values the AI suggests for custom fields now start unticked. They're read from the document's own text, so they should be accepted deliberately.
  • Bot protection is now described accurately. It raises the cost of scraping; it is not an access control, because the pass it issues isn't bound to the visitor. If the files matter, restrict them. We'd rather say this plainly than let the old wording imply a guarantee it never made.
v2.49.0

SharePoint, Box, and native Bricks + Divi elements

SharePoint and Box join the cloud storage options, and the Document Library gains native elements in two more page builders.

SharePoint and Box join the cloud set

Cloud storage now speaks to SharePoint Online document libraries — browse your sites, their libraries and folders, attach files, and serve downloads through the same short-lived per-click links as OneDrive (it's the same Microsoft Graph underneath) — and to Box, completing the set: Amazon S3 and anything S3-compatible, Dropbox, Google Drive, OneDrive, SharePoint and Box. As ever, credentials stay on your server and visitors only ever see expiring links.

Bricks and Divi get native elements

The Document Library now lives in the Bricks and Divi palettes as a native element — layout, category and colour scheme as proper controls, no shortcode to remember. Both render through exactly the same pipeline as the block and shortcode, so nothing behaves differently; and if the builder isn't installed, nothing loads at all.

Fixes & improvements

  • Translation-ready, declared: a bundled wpml-config.xml tells WPML, Polylang and friends that documents and categories translate, that file references are copied to translations (one PDF, many languages), and that each language counts its own downloads.
v2.48.0

Vault offload to S3/R2, and multisite shared libraries

Two Pro additions for heavy libraries and networks of sites.

Serve protected files from your own bucket

A busy protected library makes your web server do all the serving — every vaulted download streams through PHP. Turn on vault offload and those files are mirrored into your connected S3-compatible bucket (Amazon S3, Cloudflare R2, Wasabi, DigitalOcean Spaces, MinIO), and downloads redirect to short-lived presigned links. The bucket does the bandwidth; FileDeck keeps doing the access control — every gate runs on your server before any link is minted.

Built conservatively: the local file always remains (previews, search and checksums read it), a file not yet mirrored simply streams locally, and watermarked serving stays local on purpose — a redirect that skipped stamping would be a silent hole, and stamped beats offloaded.

One library, every site of the network

On a WordPress multisite network, [filedeck_library site="2"] renders the central site's library anywhere — a school trust's policy library on every school's site, an agency's resource library across client sites. There is exactly one library: downloads, search and signed links all point at the central site, so its access rules and activity log do the enforcing. No copies, nothing to drift.

v2.47.0

Drop-folder imports, and a proper developer surface

Two Pro additions for the people who wire FileDeck into bigger setups.

A folder of files becomes a library — and stays one

Plenty of document libraries start as a folder of PDFs on the server, uploaded over years by SFTP. Point FileDeck at any folder inside your uploads directory (Documents → Migrate) and every file becomes a document, with sub-folders becoming nested categories and file dates becoming document dates.

Turn on re-scan daily and it becomes a drop folder: put a file in, and it appears in the library within a day, filed by its sub-folder. Additive and one-way by design — a file changed in place is never re-imported (replacing a document's file is versioning's job), and tidying the folder never deletes a document.

The same safety rules as every FileDeck import apply: the folder must live inside uploads, nothing that looks like a WordPress install root is ever accepted, and only file types WordPress itself allows are imported.

The integration surface, formalised

FileDeck has had REST routes, signed webhooks and CLI commands for a while — scattered across the docs. There's now a single developer reference covering all of it, plus two new commands: wp filedeck status (counts, tier, capabilities at a glance) and wp filedeck list (documents as a table, CSV, JSON or ids — pipeable into whatever you're scripting). These surfaces are now formal: shapes change only with a changelog note.

v2.46.0

Smart collections, and custom fields that fill themselves in

Two AI-tier additions that make a large library feel curated without anyone doing the curating.

Smart collections

Categories describe how *you* filed things. A smart collection describes what a *reader* needs: "everything a new contractor needs before their first day on site" — written in plain language under Documents → Collections, published anywhere with one shortcode, and it stays current on its own as matching documents arrive. Matching is by meaning, not keywords, using the same semantic engine as the search box.

Three things worth knowing about how it's built: rendering goes through the normal library pipeline, so access rules and padlocks behave exactly as everywhere else; the query resolves as an anonymous visitor, so a collection can never bake a restricted document into a public page; and page views never call the AI provider — the document list is cached and refreshed daily, or whenever you press Refresh.

Custom fields that fill themselves in

If your documents carry custom fields — a document date, a reference number, a type — the AI suggestions box now reads them out of the document text. Each proposed value arrives pre-validated against the field's type (a malformed date is dropped before you ever see it), with its own checkbox and an editable input, so a nearly-right extraction is a keystroke away.

As with the summary and tags: the model drafts, you decide. Nothing is ever written to a document without your approval.

v2.45.0

Retention schedules, access certification, transmittals, and check-out

Four additions for libraries that answer to auditors, regulators and contract administrators — the work a document *hub* does after the documents are in it.

Retention schedules (AI tier)

"Minutes: keep 6 years. Incident reports: keep 25." Set a retention period on a category and FileDeck enforces it: when a document's time runs out it is archived (moved to draft) or trashed — never hard-deleted — automatically.

The safety posture is the feature: nothing happens until a rule exists *and* a global switch is on; the Documents → Retention screen previews everything due in the next 30 days before you flip that switch; enforcement is capped per day so a new rule over an old backlog is a visible drip, not a mass deletion; and every action is written to the activity log with the rule that caused it. Single documents can carry their own period — or an Exempt, keep forever that always wins.

Access certification (AI tier)

The quarterly ritual every security framework asks for: *who can see the restricted material, and when did a human last confirm the list?* Documents → Certification lays out every restricted category with its roles, client-area users and password state; you review, fix anything wrong where it lives, and attest. Attestations older than 90 days show as due again, and the CSV export is the evidence you hand the auditor.

Transmittals (AI tier)

Construction and engineering don't send documents, they issue them: numbered, to a named recipient, for a stated purpose, in a register. FileDeck now keeps that register — TX-numbered packages emailed as expiring signed links (no recipient account needed, no attachment size limits), the document list frozen as issued, and a CSV export for the contract file.

Fixes & improvements

  • Document check-out (Pro): claim a document while you prepare its next revision — nobody else can replace the file (or mint a version) until you check it back in. A refused swap says exactly who holds the lock, admins can always release, and forgotten locks expire after 7 days.
v2.44.0

Terms and zip downloads now work together

A fix for sites running the terms gate: multi-select zip downloads used to come back empty when terms were required, because the acceptance never reached the zip request — each document inside the archive was silently skipped rather than the reader being asked to accept first.

One acceptance now covers everything

Accepting the terms now sets a short-lived cookie, the same mechanism the form gate uses. That one acceptance covers:

  • Zip downloads — clicking the zip button now opens the terms dialog if you haven't accepted yet, and the archive contains every document it should.
  • Later downloads — a second document on the same page, or any download on another page of the site, within the hour. Previously only the single download the dialog was answered for carried the acceptance.

The record is unchanged: every acceptance still lands in the activity log with the document, time and visitor.

Fixes & improvements

  • The require-a-form gate now also opens its dialog when the zip button is clicked, instead of the archive silently skipping every document.
v2.43.0

Bot protection, mailing-list sync, and S3-compatible storage

Five Pro additions: bot protection on downloads, mailing-list sync for captured leads, S3-compatible storage, per-document download limits, and per-document passwords.

A quick check that stops download scrapers (Pro)

A public library's download links can be walked by a one-line script. Turn on bot protection and the first download of a visit asks for a Cloudflare Turnstile check — free, no ad cookies, usually passed without clicking anything. One pass unlocks downloads for an hour.

The people who shouldn't be bothered aren't: logged-in users are never challenged, signed share links skip the check as always, and multi-select zip downloads are covered by the same single check. It is enforced on the server — a script calling the download URL directly is refused, not just a dialog it never rendered.

Uses the same Turnstile keys as front-end submission, so if you set that up already, this is one checkbox.

Captured leads, straight onto your mailing list (Pro)

Lead capture asks for a name and email before a download; now those contacts can go straight to Mailchimp or Brevo — no Zapier subscription in the middle. Double opt-in is the default (new contacts confirm by email), an existing contact is never re-subscribed no matter what they download, and a Send a test contact button tells you immediately whether the key and list ID actually work. Every other provider is still reachable through the lead webhook.

S3-compatible storage: R2, Wasabi, Spaces, MinIO (Pro)

Cloud storage's S3 connection now takes a custom endpoint, so it speaks to anything that speaks S3 — Cloudflare R2, Wasabi, DigitalOcean Spaces, a self-hosted MinIO. Same signed, expiring download links; same private bucket. Fill in the endpoint, leave it blank for Amazon.

Fixes & improvements

  • Per-document download limits (Pro): expire a document after a set number of downloads — for giveaways, limited licences, or "gone when it's gone" releases. Applies to everyone, signed links included; raise or clear the limit to reopen the document.
  • Per-document passwords, properly protected: a document protected with WordPress's own post password now counts as restricted — its file moves into the protected vault so the raw uploads URL stops resolving, and listings withhold its excerpt, filename and thumbnail until unlocked. One document no longer needs its own category just to have a password.