= 2.59.12.44 = * Separate Varnish capability observation from control transport: create and verify canaries through the canonical public WordPress route while sending PURGE or BAN only to the configured control endpoint. * Restore HTTP exact-invalidation discovery for control-only listeners such as the Hetzner endpoint without requiring those listeners to serve ordinary frontend GET requests. * Preserve independent Exact PURGE and Exact BAN behavior probes and derive broader capability tests from the method verified during the current run. * Preserve terminal topology outcomes such as entire-host `not-applicable` instead of reclassifying them through generic supported/unsupported aggregation. * Persist endpoint, basic-test, HTML-variant, ESI, and aggregate capability diagnostics in existing revisioned UltraCache state records, with one-time migration from superseded diagnostic options. * Invalidate the incorrect 2.59.12.43 capability proofs through revised capability fingerprints so they cannot authorize runtime behavior before a fresh Test Varnish run. * Keep capability-probe operations isolated from production recent-operation reporting and require a specific reason for every non-executed or inconclusive capability result. = 2.59.12.43 = * Independently behavior-test HTTP Exact PURGE and Exact BAN on every configured endpoint instead of limiting probes from the configured method or adapter classification. * Derive the common production hard-invalidation method from current endpoint proofs and use the same verified method for targeted, HTML-only, and entire-host runtime operations. * Probe Batch BAN, HTML-only flush, entire-host flush, soft purge, stale refresh, and origin revalidation independently without executing known-URL or TTL production fallbacks. * Persist explicit per-endpoint capability states, reason codes, messages, applicability, conclusiveness, timestamps, and proof expiry in the existing UltraCache state table. * Distinguish supported, not supported, not applicable, observation incomplete, configuration changed, proof expired, and not tested outcomes; every untested UI result includes its specific persisted reason. * Migrate the legacy endpoint capability option into the existing UltraCache state record and remove the legacy option after successful persistence; no transient state is added. = 2.59.12.42 = * Make Automatic Varnish site flushing choose from the observed static-object route and verified production capabilities instead of preferring HTML-only flush unconditionally. * Select verified entire-host flush when public static objects pass through Varnish, and select verified HTML-only flush when public static objects bypass Varnish. * Report a verified HTML-only operation as degraded when static ownership is inconclusive or static objects pass through Varnish without verified entire-host invalidation. * Display the actual site runtime strategy in the Varnish summary: HTML-only flush, entire-host flush, known site pages, or automatic expiry. * Preserve the existing capability persistence, production transports, VCL contracts, and explicit manual scope behavior. = 2.59.12.41 = * Use one bounded post-invalidation observation contract for exact invalidation, batch BAN, HTML-only flush, entire-host flush, and static preservation proofs. * Retry transient public DNS/HTTP observation failures while still requiring two successful responses that match the expected canary generation or exact written artifact. * Fail immediately on any successful stale or mismatched observation so retries cannot manufacture a capability the production runtime does not support. * Report exhausted transport-only observations as `observation-incomplete` instead of incorrectly classifying the server capability as unsupported. * Preserve the existing production planner, control operations, capability tables, and persistent diagnostic contracts without adding transient state. = 2.59.12.40 = * Preserve the complete Varnish basic-test contract instead of truncating associative payloads by key count, recursion budget, insertion order, or string length. * Persist the full ESI capability proof and endpoint/test evidence through the existing sanitization contract. * Add an independent contract-bound HTML variant capability record and use it as the authoritative public-path registry source. * Restore the HTML variant capability into the basic diagnostic response from its dedicated record and remove the redundant capability-list slice. = 2.59.12.39 = * Classify public static delivery as Varnish bypass when the origin generation changes immediately without Varnish response evidence. * Prove the existing production HTML-only BAN with two independent cached WordPress HTML canaries instead of requiring a cacheable static object. * Persist static-bypass topology through the endpoint registry, runtime planner, and diagnostics so Automatic site flush selects direct `html-flush` rather than known-URL fallback. * Report entire-host invalidation as not applicable when static assets bypass Varnish, while retaining the original through-Varnish HTML/static proof path. = 2.59.12.38 = * Replace the per-bucket page-cache variant cap with one bounded cap over complete normalized-URL hash families. * Allow missing orig/WebP/AVIF members to complete an existing family even when another bucket already reached the path limit. * Rotate the oldest complete families under a path-level database lock, removing all bucket files, compressed/freshness/ESI sidecars, matching static aliases, and cache-asset references. * Record exact cached and failed HTML buckets plus cache-write error codes; an unsatisfied family rotation is terminal instead of retrying three times. = 2.59.12.37 = * Finalize the zero-transient regression candidate with plugin-wide enforcement that production transient reads and writes remain absent. * Verify that direct transient deletion is restricted to the final legacy migration and uninstall allowlists, with no runtime fallback to legacy values. * Validate the integrated persistent-state, lock, capability, diagnostics, queue, media, warm-up, Varnish, font-map, runtime-JS, and admin-notice contracts without adding new behavior. = 2.59.12.36 = * Replaced transient-backed admin notices with user-scoped, delete-on-read revisioned state records. * Consolidated all legacy transient cleanup into one final migration and removed superseded per-version transient migration hooks. * Enforced zero production transient reads/writes; direct deletion remains only in the named legacy cleanup and uninstall allowlists. = 2.59.12.35 = * Replace the runtime font CSS transient map with authoritative `ultracache_css_rewrite_map` reads and request-local memoization; stale generated targets are marked inactive in the same table. * Persist interim and final browser runtime JS reports in the existing `ultracache_js_diagnostic_jobs` table, merge reports under an atomic database lock, and bind standalone reports to the durable queue job when available. * Remove the runtime JS scan transient report path and the legacy media conversion-test transient fallback; existing persistent option/table contracts remain authoritative. * Add one-time cleanup for superseded font-map, runtime JS report, and media conversion-test transient keys without importing their values. = 2.59.12.34 = * Replaced transient-backed dashboard stats, storage diagnostics, page-cache activity, and last cache-event state with persistent UltraCache-owned state records. * Made normal and periodic dashboard reads DB-only; analytics counters and lightweight backend metrics refresh without scanning page-cache or object-cache storage. * Persist full object-cache measurements only from the existing explicit Count Object Cache action; capped filesystem scans run only during explicit diagnostics/count actions. * Added persistent snapshot age, stale, configuration-changed, dirty, partial, and persistence status fields without deleting historical evidence. * Added one-time legacy transient cleanup without importing transient values as authoritative state. = 2.59.12.33 = * Replace media encoder support, AVIF self-test, and GD WebP probe transients/options with fingerprinted revisioned capability state. * Replace the media library work-summary transient with a persistent dirty-aware summary rebuilt from authoritative attachment/source data after media mutations. * Replace per-format optimized-storage health transients with persistent diagnostic snapshots that retain evidence and fail closed when stale, dirty, or configuration-changed. * Remove production transient readers and writers for these media paths and add one-time cleanup without importing legacy values as capability proof. = 2.59.12.32 = * Replace the frontend compression result transient with fingerprinted revisioned state that survives object-cache eviction and reports stale or configuration-changed evidence explicitly. * Replace stored compression challenge transients with short-lived HMAC-signed tokens and atomic database replay claims; expired, modified, and repeated challenges fail closed. * Replace loopback SSL fallback history and object-cache support snapshots with persistent runtime capability state. * Remove production transient readers and writers for the three runtime/server capability paths and add one-time cleanup for superseded fixed and dynamic keys. = 2.59.12.31 = * Replaced LCP observation cleanup transients with an atomic database cooldown lease. * Replaced media affected-page cleanup, on-demand queue deduplication, and queue-init maintenance transients with database locks. * Removed the transient fallback from signed LiteSpeed control replay protection; verification now fails closed when the lock contract is unavailable. * Replaced Google Fonts cache-write retry transients with short database leases. * Added one-time cleanup for superseded fixed and dynamic coordination transient keys. = 2.59.12.30 = * Remove the legacy cron warm execution-lock transient mirror; the existing token-guarded `ultracache_locks` mutex and revisioned warm-decision fence are now the only authoritative ownership records. * Replace the cron worker-recovery throttle transient with an expiring atomic database lock while retaining the separate short-lived recovery execution mutex. * Replace per-post save warm cooldown transients with expiring atomic database locks, preserving filter-controlled cooldown duration and cross-request deduplication. * Delete the fixed legacy warm coordination transients once during upgrade and remove residual database option rows for dynamic post-save warm transient keys without migrating their values. = 2.59.12.29 = * Replaces the Varnish performance snapshot transient with revisioned persistent state, retaining measurements across object-cache flushes and marking them stale or configuration-changed instead of deleting them. * Replaces the reverse-proxy detection transient with explicit, fingerprinted persistent diagnostic state; ordinary status reads no longer issue network probes. * Refreshes reverse-proxy evidence only during explicit Detect Varnish, Test Varnish, or Measure Varnish Performance actions. * Adds one-time cleanup for the superseded Varnish diagnostic transients without migrating transient values into authoritative state. = 2.59.12.28 = * Remove the HTML/host flush, two-stage origin refill, and soft-purge capability transient readers and writers; the persistent per-endpoint capability registry is now the only source that can authorize Varnish runtime behavior. * Persist bounded aggregate topology, soft-purge, and origin-revalidation diagnostic details in the existing revisioned UltraCache state table without allowing those diagnostic records to grant a capability. * Preserve tested, unsupported, expired, and configuration-changed capability history through explicit registry timestamps and proof-expiry fields instead of deleting the state when a transient expires. * Delete the four superseded Varnish capability transient keys once during upgrade, including the already-obsolete refresh-ahead capability key. = 2.59.12.27 = * Move the latest production Varnish operation result from `ultracache_varnish_last_result` transient storage to the existing revisioned `ultracache_locks` state table under `ultracache_state:varnish.last_operation`. * Make Varnish diagnostics, REST status, and WP-CLI consume the same persistent operation-state record, so object-cache eviction or transient expiration cannot erase the latest result. * Link completed `varnish_flush_all` dashboard actions to the persistent operation result with the durable action-job ID and timestamps after the action-job row is saved. * Delete the superseded transient once through a persistent migration marker; no production reader or writer falls back to it. = 2.59.12.26 = * Verify each post-BAN canary refill against the exact generation 2 artifact written by UltraCache, using the deterministic body marker, body hash, or canary ETag as equivalent object-identity evidence. * Preserve the production capability contract: a successful two-URL Batch BAN proof now activates bounded runtime and queued batching, while failed, expired, or unavailable proof continues to use exact BAN per URL. * Record per-canary post-BAN verification evidence without changing the Varnish transport, planner policy, UI layout, Detect flow, or fallback behavior. = 2.59.12.25 = * Align durable queued Admin/HTTP BAN execution with the same current Batch BAN capability used by the direct targeted runtime and request estimator; unverified batching now produces one exact BAN operation per URL and endpoint. * Downgrade a failed verified batch expression to exact-per-URL fallback first, preserving independent Exact BAN proof until that fallback itself fails. * Complete capability-driven regression coverage for targeted, queued, site-wide, soft-purge, known-URL, and TTL strategies, including planner, registry, queue accounting, UI truth states, and production Flush All delegation. * Assert that Varnish capability probes use production execution paths and that no diagnostic-only Batch BAN, HTML/host flush, or soft-PURGE transport remains. = 2.59.12.24 = * Route the HTTP soft-purge capability proof through the production targeted invalidator, including production URL normalization, scoped planner authorization, endpoint selection, transport, and runtime result accounting. * Remove the diagnostic-only soft-PURGE request executor; canaries now provide observation only and pre-transport failures remain Not tested. * Permit the internal soft strategy override only for an exact matching endpoint-and-URL capability probe; outside that probe UltraCache retains its current verified strategy or hard exact fallback. * Run authenticated origin-revalidation proof only after at least one configured endpoint accepts the production soft-PURGE operation, and bind endpoint origin evidence only to endpoints that completed that transport step. = 2.59.12.23 = * Route HTML-only and entire-host capability proof through the production site-flush planner, scope executor, adapter, transport, and endpoint accounting used by Flush All. * Remove the diagnostic-only scope-expression executor and its HTML/host test wrappers; canaries now provide observation only and never send a separate invalidation command. * Test HTTP data-plane endpoints independently, while treating multiple Admin sockets as one configured production endpoint set whose aggregate behavior is observed on the canonical public path. * Preserve Not tested for unavailable canaries or non-executed runtime plans, and persist broad-scope support only after the production operation is accepted and the required HTML/static behavior is observed. = 2.59.12.22 = * Route the two-URL Batch BAN capability proof through the production targeted invalidator instead of a diagnostic-only BAN executor. * Use current Batch BAN proof to choose one bounded shared BAN expression; when only exact BAN is verified, send one exact BAN expression per URL through the same production path. * Treat production normalization, deduplication, or transport precondition failures as Not tested when no request was sent, without adding canary URL bypasses. * Persist Admin exact and batch behavior only when the complete configured control-endpoint set accepts the production operation and the public canary exposes the expected refill; align queue request estimates with the same batch-or-exact runtime decision. = 2.59.12.21 = * Replace the general Varnish test-run authorization bypass with a request-local capability probe bound to one operation, strategy, scope, endpoint set, and target-URL fingerprint. * Require matching scoped authorization before the targeted runtime planner, authenticated exact-PURGE contract, direct diagnostic BAN transport, soft-PURGE diagnostic, or diagnostic refill may exercise an unverified path. * Keep the existing test-depth state only for production metric/result suppression and bounded runtime side-effect deferral; a test run by itself no longer grants any invalidation capability. * Preserve the canonical HTML-variant warm pipeline by opening a nested exact-URL probe only for its production pre-refill invalidation of the same URL and configured endpoints. = 2.59.12.20 = * Prevent cache-plugin signature labels from invoking the UltraCache text domain during early drop-in reconciliation before WordPress init. * Preserve translated labels from init onward through the existing lifecycle-aware translation helper, without suppressing WordPress diagnostics or changing reconciliation timing. = 2.59.12.19 = * Preserve independently verified Batch BAN, HTML-only, entire-host, soft-purge, origin-revalidation, and SWR evidence when another capability is skipped or retested; runtime failures now downgrade only the affected topology scope. * Bind HTML-variant and ESI evidence to public-path contracts instead of the Admin/HTTP control-plane identity, while retaining independent expiry and configuration-change truth. * Report Not tested, Not supported, Proof expired, partial, and verified states consistently through the capability registry, runtime planner, stored diagnostics, and Varnish dashboard. * Complete executable regression coverage for Admin/HTTP exact invalidation, contract-only advertisements, multi-endpoint intersection, proof expiry, configuration changes, soft-purge state, public-path scope, performance fingerprinting, and UI presentation. = 2.59.12.18 = * Connect Test Varnish in HTTP Soft or Automatic mode to a per-endpoint soft-PURGE canary that requires cached generation 1, a high-confidence STALE response after origin changes to generation 2, and a stable generation-2 HIT after bounded revalidation polling. * Execute the existing authenticated origin-revalidation contract during the same diagnostic and require WordPress origin proof for every active HTML variant before runtime soft purge is enabled. * Persist independent soft-purge, origin-revalidation, and SWR tested state bound to the current soft/refill configuration; skipped preconditions preserve current proof, while real behavior failures fail closed without downgrading independent exact invalidation. * Expand the performance snapshot fingerprint to include Varnish mode, endpoints, PURGE/BAN method, a non-reversible secret fingerprint, endpoint VCL contract identity/capabilities, public-path capabilities, and HTML-variant policy. = 2.59.12.17 = * Separate control-endpoint invalidation capabilities from site/public-path ESI and HTML-variant behavior without changing the Varnish settings or Detect workflow. * Verify Batch BAN with two isolated WordPress-served canaries and one real batched expression instead of deriving it from exact BAN support. * Verify HTML-only and entire-host invalidation independently with cached HTML and opaque static canaries, bypassing only the existing behavior-proof gate during the diagnostic command. * Keep HTTP contract advertisements as metadata until their matching behavior proof succeeds, report per-capability Not tested/Not supported/verified truth, and fail closed when multiple Admin sockets cannot be mapped to individual public data paths. = 2.59.12.16 = * Distinguish an authenticated Varnish control connection from command acceptance and exact cache invalidation proof in Admin mode. * Report connected generic VCL setups accurately while leaving exact BAN, batch BAN, HTML-only flush, and host flush unavailable until their existing behavior proofs succeed. * Remove contradictory connection warnings and non-expiring Admin proof labels, and show bounded proof expiry plus exact per-endpoint status from the capability registry. * Preserve the 2.59.12.15 fail-closed runtime planner and existing HTTP PURGE/BAN behavior without adding automatic tests or changing the Varnish settings workflow. = 2.59.12.15 = * Stop deriving exact BAN, batch BAN, HTML-only flush, and entire-host flush runtime capabilities from Admin mode or endpoint reachability alone. * Require current isolated-canary proof and bounded expiry for Admin exact BAN behavior, while preserving the existing HTTP PURGE/BAN proof path. * Keep public canary reachability separate from authenticated admin control acceptance and fail closed after a newer behavior test contradicts an older proof. * Downgrade affected endpoint capabilities after failed runtime invalidation so the planner selects the next verified fallback instead of repeating a stale strategy. = 2.59.12.14 = * Discard the disposable cron warm queue and coordination runtime during the supported SVN/private upgrade reset instead of migrating pending, processing, or legacy job rows. * Remove the self-referencing legacy warm-row consolidation and metadata-compaction upgrade path that could issue ambiguous `source_context` SQL. * Recreate any outdated warm queue schema as an empty current queue, gate non-owner requests while the reset is incomplete, and preserve all user configuration. * Serialize the shared locks-table dbDelta prerequisite with a narrow expiring bootstrap option lock and verify the required columns and indexes before marking schema version 2 complete. = 2.59.12.13 = * Complete the Media Library Replacement publication regression pass across block, reuse, overwrite, rollback, restart, verification, and cleanup paths. * Preserve a pre-existing or externally changed destination when a failed publication cannot prove that the current file is the exact UltraCache output from that attempt. * Remove partial replacement temporary files and overwrite backups when a filesystem copy reports failure, and align release documentation/version metadata. = 2.59.12.12 = * Publish Media Library Replacement AVIF/WebP destinations through verified same-directory temporary files and atomic commits instead of direct overwrite copies. * Stop and report different existing destination files by default, while allowing an explicit Overwrite with verified backup policy that remains rollback-capable until Delete Originals completes. * Persist previous and published destination fingerprints in the existing replacement registry, restore backups during rollback or Prepare restart, and block cleanup when ownership can no longer be proven. * Prevent overwrite policy from resolving two same-job registry rows that require different bytes at the same Media Library destination. = 2.59.12.11 = * Restore atomic upload-conversion commits for AVIF/WebP destinations beside normal Media Library attachments instead of limiting the guarded commit path to uploads/ultracache. * Restrict the upload-tree write allowance to exact same-directory `.uc-tmp-*` AVIF/WebP commit pairs plus the converter's final-output cleanup and freshness contexts. * Preserve all generic filesystem guards and reject cross-directory, cross-format, non-image, and outside-uploads operations. = 2.59.12.10 = * Ensure the media queue schema upgrade completes before stale-worker recovery can read or update the persistent `stale_recoveries` counter. * Prevent upgrades from older queue schemas from issuing recovery SQL against a column that has not yet been added. = 2.59.12.09 = * Consolidate the independent Upload, Rewrite, Rewrite Fallback, and Media Library Replacement format policies into the full media regression candidate without adding a second queue, encoder framework, replacement workflow, or browser detector. * Clarify Original file fallback throughout the dashboard and Help because the current attachment may be JPEG, PNG, AVIF, or WebP after upload conversion or Media Library Replacement. * Complete the release-wide media matrix, migration, explicit replacement generation, AVIF-source capability, queue, rewrite, warm-up, syntax, translation, and package regression gates. = 2.59.12.08 = * Admit AVIF Media Library and upload sources to the existing WebP pipeline only when the same Imagick or GD engine passes the AVIF decode and WebP encode self-test. * Extend the established generated-path, queue rebuild, on-demand, HTML/CSS rewrite, upload-conversion, and conversion-test contracts to support AVIF-to-WebP without a second pipeline. * Treat an AVIF source as the existing AVIF result, preserve animated AVIF sources, and keep browser selection on the existing Accept-based orig/WebP/AVIF cache buckets. = 2.59.12.07 = * Extend the existing AVIF self-test with an independent bundled AVIF source fixture so decode capability no longer depends on AVIF encode support. * Report verified Imagick and GD AVIF decode plus AVIF-to-WebP capability separately while keeping the established AVIF encoder support contract unchanged. * Expose the new codec capability results in media diagnostics without enabling AVIF production source admission yet. = 2.59.12.06 = * Queue missing, stale, or invalid Media Library Replacement targets as exact AVIF or WebP rows in the existing media queue. * Process only the candidate attachment IDs discovered by each bounded readiness chunk while preserving queue locks, pause controls, stale recovery, and the existing three-attempt failure limit. * Repeat the readiness verification pass until every generated target is valid and current before Prepare can unlock. = 2.59.12.05 = * Connected Media Library Replacement to the independent Image replacement format instead of Image Rewrite Format. * Reused the existing readiness and Prepare policy guards so pre-Do plans are rebuilt when the replacement target changes. * Locked replacement-format changes after destructive Do work begins while preserving the existing completion and recovery paths. = 2.59.12.04 = * Connected Convert new uploads to the independent Upload image format setting instead of the frontend rewrite policy. * Renamed Image Output Format and Fallback Format to Image Rewrite Format and Image Rewrite Fallback Format without changing queue, rewrite, cache-variant, or warm-up behavior. * Kept shared image quality, color-profile policy, and conversion-test controls available when Media Rewrite is disabled. = 2.59.12.03 = * Added canonical Upload Image Format and Image Replacement Format settings. * Existing installations inherit both new formats from the saved Image Output Format. * Added runtime, REST, and settings import/export support without changing media execution behavior. = 2.59.12.02 = * Treat color-profile policy outcomes as semantic media skips instead of retryable encoder failures, preserving the exact skip reason and detail. * Continue AVIF-with-WebP queue work to the WebP unit in the same request when AVIF is skipped, and complete the attachment without three failed retries. * Add the default-off Ignore color profile preservation media setting so generated AVIF/WebP variants may discard unverifiable ICC/ICM metadata while original images remain unchanged. = 2.59.12.01 = * Restore native parse_url() in every early-bootstrap advanced-cache URL parsing path because wp_parse_url() is not defined when WordPress loads the drop-in. * Document each unavoidable native parser call precisely for Plugin Check without changing host, request, LiteSpeed, ESI, or cache-key validation behavior. * Add an early-bootstrap regression gate that executes the generated advanced-cache drop-in with no wp_parse_url() function available. = 2.59.12.00 = * Detect the WordPress login request before frontend hook registration, using the native login predicate with bounded script-path fallbacks. * Keep JavaScript defer/delay, stylesheet rewriting, resource hints, frontend helpers, and HTML output transforms completely detached from wp-login.php. * Preserve cache invalidation hooks and normal public frontend optimization behavior without adding script-specific CAPTCHA or Clipboard exclusions. = 2.59.11.99 = * Route advanced-cache request headers and signed query controls through the existing normalized server/query helpers and use WordPress URL parsing. * Reuse the existing object-cache lock acquisition and release paths, retaining narrowly documented native primitives only where flock handles are required. * Resolve the remaining runtime translation, filesystem-probe, and iframe request-input Plugin Check findings without changing cache policy or backend behavior. = 2.59.11.98 = * Exclude the entire development tests directory from the installable production ZIP. * Keep the complete parity and live validation suites in the development source tree and run them before packaging. * Add a package-level regression check that rejects tests, test harnesses, and development-only PHP files in the production archive. = 2.59.11.97 = * Render Per-endpoint proofs with the same horizontal label/value rows used by the upper Varnish diagnostics cards. * Render Recent operation and failures with that same horizontal row contract instead of vertical DetailRow blocks inside a nested grid. * Add a regression gate that verifies both lower diagnostics cards use the shared horizontal renderer and contain no vertical label-above-value rows. = 2.59.11.96 = * Keep Automation-owned stale-while-revalidate response grace active in Admin/BAN mode instead of incorrectly requiring HTTP soft-purge capability. * Replace the ambiguous HTML variants boolean with explicit supported, not-applicable, expired, configuration-changed, incomplete, or failed states plus active-bucket and per-bucket evidence. * Place Per-endpoint proofs and Recent operation and failures in one deterministic responsive diagnostics row. = 2.59.11.95 = * Let Varnish 5.2 derive object grace from the dynamic Cache-Control stale-while-revalidate value produced by Automation & Scheduling instead of overriding every object with a fixed 10-minute grace. * Emit stale-while-revalidate explicitly for cacheable shared responses, including 0 when SWR is disabled or Max stale equals Fresh TTL, so Varnish does not fall back to its default grace. * Keep the independent 5-minute Varnish keep window and all existing TTL, invalidation, refill, ESI, endpoint, and template-selection contracts unchanged. = 2.59.11.94 = * Replace the two bundled Control Web Panel Varnish alternatives with one canonical fail-closed WordPress/WooCommerce/ESI template. * Expose one dashboard Help download and preserve the existing CWP placeholders, local exact PURGE, object metadata, Accept variants, ESI transport, and request/response approval handshake. * Remove obsolete template files, runtime data, documentation, and translation strings without changing Varnish settings, invalidation behavior, grace, or keep. = 2.59.11.93 = * Convert native Varnish Admin exact, batched, HTML-only, and entire-host BAN commands from portable request predicates to the bundled CWP object metadata contract before socket transport. * Reuse the same bounded object-expression converter as the authenticated HTTP BAN contract and reject unsupported request predicates before opening the admin connection. * Keep generic HTTP PURGE/BAN expressions, endpoint settings, capability policy, direct thresholds, queue scheduling, and CWP templates unchanged. = 2.59.11.92 = * Run persistent Varnish invalidation independently from Background warm pages per minute, using only the dedicated Varnish operations-per-minute budget. * Keep refill, refresh-ahead, LiteSpeed auxiliary work, and ordinary page warming paused when the page rate is 0. * Preserve UI/WP-CLI foreground priority, automatic retry/minute-window scheduling, and explicit worker status for independent invalidation. = 2.59.11.91 = * Connect queued Varnish invalidations to the dedicated atomic real-minute operation budget instead of charging URL rows to the page warm-rate budget. * Count one operation for each exact PURGE or bounded BAN batch sent to one configured endpoint, including endpoint-specific retry work. * Persist successful endpoint progress across limited budgets, leave unattempted endpoints immediately pending without increasing retry attempts, and increment retries only for actual transport failures. = 2.59.11.90 = * Add a dedicated revisioned Varnish invalidation-rate state with atomic compare-and-swap operation claims. * Preserve the current real-minute allowance when the setting increases, apply lower ceilings immediately, and reset claims only at a new real-minute window. * Synchronize the dedicated state after settings saves while leaving Varnish queue dispatch, scheduling, and direct invalidation behavior unchanged. = 2.59.11.89 = * Add Varnish invalidations per minute to the canonical dashboard, REST, CLI, import/export, and runtime settings contracts. * Default the bounded setting to 10 operations per minute with an accepted range of 1–600, independently from page warm-up speed. * Preserve the setting across performance-profile changes and leave all Varnish queue, scheduling, and direct-invalidation behavior unchanged for this version. = 2.59.11.88 = * Connect `jQuery(...).METHOD is not a function` diagnostics to the existing bounded active plugin/theme JavaScript filesystem scan. * Resolve exact jQuery plugin provider definitions and consumer calls even when the provider script is absent from the page inventory. * Return the exact consumer with an explicit provider-not-found result instead of producing zero suggestions. = 2.59.11.87 = * Register `lazyLoadThirdPartyIframesEnabled` in the existing REST settings schema so the Media Optimization switch persists through normal settings save and response synchronization. * Keep the iframe eligibility, exclusions, viewport activation, runtime, UI, defaults, and storage structure unchanged. * Add an executable REST save round-trip regression covering `false -> true -> false` persistence and returned patch/settings values. = 2.59.11.86 = * Add a Media Optimization switch for strict viewport-based lazy loading of eligible third-party iframes such as Google Maps and video embeds. * Keep payment, authentication, CAPTCHA, hidden or zero-dimension functional frames, explicit eager/opt-out frames, and critical cart/checkout/account requests unchanged. * Replace eligible iframe sources with inert placeholders, restore them 400 pixels before the viewport or on interaction through an external runtime, and preserve a no-JavaScript fallback without adding a timer or permanent provider exclusion UI. = 2.59.11.85 = * Decouple CSS Bundle Exclusions from local stylesheet media rewriting so excluded Elementor, theme, and plugin stylesheets remain separate but can still use generated AVIF/WebP background URLs. * Create one-to-one `optimized-css/css-media-*.css` mirrors only when at least one local background image URL is actually rewritten, preserving stylesheet order, media attributes, imports, and all non-rewritten relative URLs. * Keep the media stylesheet pass independent from font settings and bundling decisions, with atomic output writes and a dedicated `css-media-rewrite` source map. = 2.59.11.84 = * Add a false-by-default `needs_main_query` ESI fragment contract and opt only the built-in private WooCommerce classic mini-cart out of the WordPress main posts query. * Short-circuit `posts_pre_query` only for GET/HEAD main queries carrying a valid signed token for an enabled fragment whose registered definition explicitly declares that main-query state is unnecessary. * Preserve WordPress and WooCommerce bootstrap, cart/session initialization, private cookie transport, renderer output, no-store headers, public ESI, and all custom fragments unless they explicitly opt out. = 2.59.11.83 = * Display the existing rolling 24-hour ESI metrics inside Varnish Diagnostics for all ESI fragments and the WooCommerce mini-cart adapter. * Show sampled and estimated request volume, estimated request rate and public/private mix, render duration, output size, and contained errors without changing the metrics backend. * Keep zero-sample states neutral, surface contained errors even without sampled renders, and warn on the existing Woo mini-cart meaningful-traffic and 100 ms render-cost threshold. = 2.59.11.82 = * Add a query-string caching guidance step between the Delay non-critical/local JS and selective-options steps in the Help popup performance section. * Direct administrators to enable Query-string args caching, populate and save the Query-string args whitelist, with `/YourProductURL?color=red` as the example. * Keep the Help action informational only; no setting is changed automatically. = 2.59.11.81 = * Restore the public stem-based generated image identity, mapping `photo.jpg` and `photo.png` to `photo.avif`/`photo.webp` so existing optimized files remain immediately reusable. * Extend WordPress unique filename selection across JPG, JPEG, PNG, and WebP source stems inside uploads, using `-2`, `-3`, and later suffixes to prevent new generated-variant collisions. * Keep the correction free of automatic scans, regeneration, legacy detectors, cleanup UI, settings migrations, and frontend fallback lookups. = 2.59.11.80 = * Consolidate the verified strict-CSP async CSS, profiler input limits, quote-aware tag discovery, exact WordPress provider resolution, and LCP/SR7 winner contracts into one regression candidate. * Add one executable release gate proving the 2.59.11.72-2.59.11.79 contracts coexist without a settings, schema, or warm-runtime migration change. * Keep production runtime behavior identical to 2.59.11.79; this version adds package identity, integration evidence, and final release validation only. = 2.59.11.79 = * Use score, then rendered area, then DOM offset for whole-document generic LCP heuristic selection, matching the existing frontend optimization path. * Order mixed Slider Revolution fallback candidates by explicit semantic origin before area, preserving area-first ordering inside each origin class. * Add executable expected-winner fixtures for logo, hidden, navigation, featured-image, verified first-slide, static-slide, explicit-tag, and raw-fallback cases. = 2.59.11.78 = * Keep the bare `wp` namespace unresolved instead of treating `wp-util` as its provider. * Resolve explicitly named WordPress packages through exact registered handles or exact `wp-includes` core paths, including `wp.element` and `wp.data`. * Add final profiler-response fixtures for bare `wp`, `wp.template`, `wp.i18n`, `wp.hooks`, `wp.apiFetch`, `wp.domReady`, `wp.element`, and `wp.data`. = 2.59.11.77 = * Move confirmed module-background, marked SR7 image, static-context, generic SR7 image, generated image-list mapping, and manual SR7 tag discovery to the shared quote-aware raw tag scanner. * Replace the 480-character URL proximity classifier with actual opening-tag and enclosing SR7 container context, including explicit candidate origins and structural first-slide markers. * Preserve existing score constants, area-first comparators, first/static-slide paths, and browser-observed LCP contracts. = 2.59.11.76 = * Move generic WordPress featured-image LCP fallback discovery from the unsafe `]*>` boundary regex to the shared quote-aware raw tag scanner. * Preserve original tag bytes and exact byte offsets so navigation exclusion, article context, scoring, candidate hydration, and winner behavior remain unchanged for ordinary markup. * Correct the JSON-LD primary-image pattern escaping found by the new executable fixture, eliminating the invalid-regex warning while retaining the existing metadata identity contract. * Keep manual selector, manual URL-equivalence, SR7 discovery, browser observations, viewport policy, and comparator behavior unchanged. = 2.59.11.75 = * Add one dependency-free quote-aware raw HTML tag scanner that preserves original bytes, exact start/end offsets, allowed custom tag names, and fail-closed handling for unterminated quoted attributes. * Migrate browser-observed LCP preload duplicate detection and empty external-script boundary collection away from `[^>]*` opening-tag regexes, preserving attributes that follow quoted `>` characters. * Keep generic LCP/SR7 candidate discovery, HTML tree semantics, and script inner-content extraction unchanged for their dedicated later roadmap gates. = 2.59.11.74 = * Add a dependency-free quote-aware reference scanner and fixture matrix for `>` inside single- and double-quoted image, link, script, and SR7 attributes. * Map each active regex caller to its actual impact, separating diagnostic-only count errors, duplicate-preload risk, optimization omissions, fallback LCP/SR7 candidate omissions, and script inner-content contracts. * Keep production runtime behavior unchanged while making raw-tag bytes, start/end offsets, context policy, and fail-closed requirements executable gates for the next parser-hardening version. = 2.59.11.73 = * Bound pasted profiler console input to 256 KiB and 2,000 lines before sanitization, parsing, queue storage, and diagnostic processing. * Preserve valid UTF-8 and complete lines where possible, while keeping accepted console content beyond the previous hidden parser slice available to the diagnostic engine. * Return explicit truncation state, byte and line counts, reasons, and active limits in direct and queued profiler results without changing matching rules. = 2.59.11.72 = * Replace inline async-stylesheet `onload` handlers with one external WordPress-enqueued activation runtime compatible with strict Content Security Policy. * Preserve each managed stylesheet's intended media target while retaining the existing DOM position, eligibility decisions, and noscript fallbacks. * Cover general Async CSS, Critical Request Chain delayed stylesheets, and delayed icon-font CSS with executable PHP and JavaScript regression fixtures. = 2.59.11.71 = * Correct live AVIF engine classification when GD exposes imageavif() but has no runtime encoder codec. * Validate failed-regeneration atomic preservation against the selected encoder directly instead of the sample conversion wrapper. = 2.59.11.70 = * Add a packaged WP-CLI live-runtime validation gate for actual host AVIF/WebP encoders, color management, EXIF orientation, animation policy, decoder admission, atomic replacement, freshness, semantic HTML/srcset behavior, and balanced font CSS parsing. * Bundle deterministic EXIF orientation 1-8, animated/static WebP, and pixel-expectation fixtures used by the live gate without touching Media Library originals or persistent settings. * Keep production runtime behavior, settings, and database schemas unchanged from 2.59.11.69; this build adds the final host-validation candidate and executable package contract only. * Require the live JSON report to contain zero failures before the roadmap may be declared complete; unavailable encoder engines are reported separately as skips. = 2.59.11.69 = * Add one integrated UC-032 through UC-045 regression-candidate matrix that executes every dedicated media conversion, generated-variant, responsive-image, semantic HTML, and font-parser fixture. * Audit all active media writer, generated-path, srcset, HTML rewrite, and `@font-face` call sites, with package-wide assertions that reject superseded direct writers, ambiguous filenames, global URL maps, and unsafe structural parsers. * Route browser-observed LCP `srcset` matching through the shared comma-safe tokenizer, closing the remaining Cloudinary/imgix candidate-matching gap found by the integrated call-site inventory. * Keep settings and database schemas unchanged; this release adds regression evidence plus the bounded LCP observation integration correction. = 2.59.11.68 = * Replace every active regex-based `@font-face` structural parser with one bounded scanner that respects comments, quoted strings, escapes, and balanced braces. * Rewrite only exact block and declaration byte ranges, preserving untouched CSS and explicit `font-display: optional`, `fallback`, or `swap` values while normalizing only missing, `auto`, or `block` declarations. * Fail closed on unclosed comments, strings, parentheses, or blocks, leaving malformed third-party CSS byte-for-byte unchanged instead of attempting repair. * Share the scanner across font discovery/storage, inline and linked font rewriting, delayed icon-font splitting, REST font-pattern analysis, and diagnostics, with executable malformed and punctuation-heavy fixtures. = 2.59.11.67 = * Replace the full-document upload URL `str_replace` map with the same tag-aware media policy used for filtered fragments, so identical URLs keep their semantics in images, downloads, metadata, and JSON. * Rewrite `src`, lazy-source, and srcset attributes only on explicit image surfaces, while preserving generic anchor `href`, `data-href`, iframe/link sources, and non-image inputs. * Keep `data-lg-src`, `data-mfp-src`, explicit background attributes, and inline background URLs supported without rewriting Open Graph or Twitter image metadata. * Add executable full-document and fragment fixtures proving image replacement, download preservation, format-stable social metadata, lightbox compatibility, JSON preservation, and removal of obsolete rewrite-map state. = 2.59.11.66 = * Replace raw comma splitting with one shared srcset parser used by media HTML rewriting, LCP candidate discovery, and both protocol-relative engine normalization paths. * Treat commas inside Cloudinary/imgix-style URLs, query strings, and data URIs as URL content while retaining top-level candidate separators and descriptors. * Rewrite only URL byte ranges, preserving untouched candidates, delimiters, and whitespace exactly; return the original srcset byte-for-byte when no URL changes. * Add executable fixtures for width/density descriptors, URL-only candidates, mixed local/CDN values, data URIs, protocol-relative URLs, regex fallback, and WP HTML Tag Processor execution. = 2.59.11.65 = * Verify generated AVIF/WebP freshness against the exact source file before frontend rewrite, serving a variant only when both mtimes are valid and the output is at least as new as the source. * Fall back to the original image for missing, stale, orphaned, or unverifiable variants, without deleting or rewriting files inside the frontend request. * Reuse the bounded on-demand media queue with source mtime/size dedupe for stale and indeterminate discoveries, while memoizing source fingerprints and freshness states per request. * Align newly committed output timestamps to future-dated sources when required, and add executable regressions for replacements, missing sources, unknown mtimes, queue dedupe, non-destructive lookup, and timestamp alignment. = 2.59.11.64 = * Retain the complete source filename in every generated AVIF/WebP path, mapping `photo.jpg` to `photo.jpg.avif` or `photo.jpg.webp` instead of removing the source extension. * Add one canonical generated-path builder and exact reverse mapper shared by media generation, frontend lookup, LCP preference, Slider Revolution handling, and converted-image source recovery. * Stop guessing source extensions and intentionally reject legacy ambiguous optimized names that cannot distinguish sources such as `photo.jpg` and `photo.png`. * Apply the same collision-free identity to Media Library Replacement plans and add executable regressions for generation, serving, reverse mapping, Slider Revolution, and replacement destinations. = 2.59.11.63 = * Detect embedded JPEG APP2 ICC, PNG iCCP, and WebP ICCP metadata through bounded guarded reads before selecting an encoder. * Route profiled or indeterminate sources exclusively through color-managed Imagick paths, including upload max-side resize inside the same bounded decode, while preserving the original upload when color management is unavailable. * Preserve ICC/ICM bytes across metadata stripping, verify the real temporary AVIF/WebP output before atomic publication, and convert decoded pixels through a bundled sRGB profile when the delegate drops the original profile. * Extend the AVIF runtime self-test with a valid profiled JPEG fixture, separate color-profile capability, and decoded-output RGB sample comparison against a runtime-generated sRGB reference. = 2.59.11.62 = * Parse JPEG APP1/Exif orientation through bounded guarded reads without depending on the optional PHP EXIF extension. * Normalize the complete EXIF orientation matrix 1–8 before encoding, including mirrored cases 2, 4, 5, and 7, through native or manual Imagick operations and explicit GD pixel transforms. * Reset Imagick output to top-left before metadata stripping and route oriented WebP sources away from the non-portable WordPress image-editor path into the shared normalized encoder paths. * Add executable fixtures for little- and big-endian EXIF metadata, malformed/truncated tags, all eight GD pixel matrices, native/manual Imagick operations, alpha handling, and decode-normalize-encode ordering. = 2.59.11.61 = * Detect animated WebP sources before pixel decode through bounded RIFF chunk inspection and resource-limited Imagick metadata frame counting. * Complete queue, direct, bulk, forced-regeneration, and conversion-test work as an explicit `animated_webp_unsupported` skip instead of recording an encoder failure or retrying the item. * Preserve animated WebP uploads before any WordPress image-editor resize, return the original upload without an error, and never delete or replace the source. * Add executable fixtures for VP8X, `ANIM`, `ANMF`, malformed containers, Imagick inspection order, queue completion, direct calls, upload preservation, and sample conversion reporting. = 2.59.11.60 = * Route WordPress image-editor, direct Imagick, and GD AVIF/WebP encodes through same-directory temporary files that retain the real output extension. * Validate temporary media output before publication, atomically rename it into place, verify the final state, harden permissions, and remove temporary files on every failure path. * Preserve any previously valid optimized destination when an encoder or commit fails, and prevent the guarded rename fallback from deleting an existing target before replacement succeeds. * Add executable atomic-output fixtures covering successful replacement, invalid temporary output, failed commit preservation, cross-directory rejection, writer call-site coverage, and guarded rename semantics. = 2.59.11.59 = * Inspect source dimensions with `wp_getimagesize()` before constructing WordPress, Imagick, or GD pixel decoders, with bounded dimension and total-pixel ceilings and overflow-safe arithmetic. * Estimate GD decoded bitmap memory as width × height × 4 × 1.8 plus allocator overhead, reserve current PHP headroom, and reject unsafe GD or unknown WordPress image-editor attempts before decode. * Construct Imagick empty, apply bounded MEMORY and MAP resource limits before `readImage()`, restore prior process limits in `finally`, and report typed preflight/decode failures. * Add executable decoder-admission fixtures covering geometry memoization, invalid/excessive sources, bounded filters, GD and WordPress memory rejection, resource-backed Imagick admission, and real conversion call ordering. = 2.59.11.58 = * Add a dedicated persistent `stale_recoveries` counter to media queue schema version 4 instead of treating work-unit attempts or ordinary conversion failures as worker crashes. * Recover expired processing claims atomically, preserve `attempts` and `consecutive_failures`, and quarantine an item after the bounded stale-recovery limit so the next pending attachment can continue. * Report stale-worker quarantine separately from normal conversion retry exhaustion, while explicit Retry Failed, regeneration, repair, and queue rebuild operations reset the appropriate failure state. * Add executable stale-worker recovery fixtures covering three consecutive abandoned claims, terminal quarantine, next-item progress, and explicit manual retry reset. = 2.59.11.57 = * Complete the full audit regression candidate with one executable UC-001 through UC-031 source-contract matrix registered in the permanent parity harness. * Require release identity parity across the plugin header, runtime constant, WordPress stable tag, README, translation template, and changelog before the candidate can pass. * Re-run the complete page-cache, object-cache, ESI, Media Queue, Media Replacement, delayed JavaScript, CSS, LCP, Varnish, REST, lifecycle, and package-hardening regression matrix as one release gate. * Keep production runtime behavior, settings schemas, and upgrade behavior unchanged from 2.59.11.56; this version adds only regression evidence and release metadata. = 2.59.11.56 = * Remove the unused object-cache `_exists()` helper after confirming that no runtime or generated-drop-in path calls it, while retaining the public WordPress-compatible key-validation contract. * Replace the ambiguous REST `format_batch_response()` helper with `paginate_complete_item_set()`, deriving `total` from the complete input set so pagination metadata cannot describe a different dataset. * Clamp past-end offsets to the actual global total, normalize item keys and page-size bounds in one canonical helper, and update both crawl-URL fallback callers to declare the complete-set contract explicitly. * Add executable fixtures for first, middle, final, empty, exact-boundary, past-end, normalized-key, and 500-item-cap pagination together with source assertions for the removed dead code and superseded helper. = 2.59.11.55 = * Store the advanced-cache and object-cache PHP source templates as guarded `.php` files so ordinary web-server configurations execute the direct-access guard instead of returning the template source as plain text. * Update both authoritative drop-in builders and all parity fixtures to consume the new template paths while preserving the generated drop-in source contract and placeholders. * Keep the CWP Varnish configuration resources as downloadable `.tpl` files and add permanent package fixtures for template filenames, direct execution, source references, placeholders, and readme sections. * Add WordPress.org Frequently Asked Questions and Upgrade Notice sections with the installed drop-in filename and upgrade behavior documented explicitly. = 2.59.11.54 = * Require every destructive Media Replacement confirmation token to match the current job, generation, action, WordPress user, and shared ten-minute TTL; expired or mismatched tokens are omitted from workflow responses. * Consume database and Theme CSS start-confirmation tokens exactly once, persist action-specific server-side authorization for later chunks, pause/resume, and WP-CLI runs, and reject raw-token replay. * Rotate the matching token and invalidate prior authorization whenever a new preview is requested, clear authorization after successful action completion, and keep a generation or user change fail-closed. * Pause Do for recoverable confirmation refresh instead of marking the replacement plan failed, and add executable fixtures for expiry boundaries, wrong job/action/user/generation, replay, preview rotation, pause/resume, completion cleanup, Delete Originals parity, and WP-CLI user zero. = 2.59.11.53 = * Replace magic zero-expiry capability handling with a data-driven fail-closed registry that reports contract support, current transport reachability, behavior verification, expiry, and effective runtime availability separately. * Keep native admin BAN, batch BAN, HTML-only, and entire-host contracts configured but unavailable until each admin endpoint accepts a real Test Varnish control request; a later failed recheck immediately removes runtime availability without erasing the historical contract record. * Preserve historical HTTP capability proof after a failed canary for diagnostics while gating runtime use through explicit per-capability availability fields; semantic VCL contract downgrade remains the authoritative path that removes superseded contract evidence. * Remove `SERVER_NAME` from discovery and enforce configured endpoint, loopback, server/local IP, local hostname, then reverse-DNS priority with executable registry, runtime-planner, recheck, unknown-capability, expiry, and candidate-order fixtures. = 2.59.11.52 = * Replace the broad refresh-ahead queue-busy check with a typed scanner gate that yields only to an active foreground warm-up owner, pending or processing Varnish invalidation, or a paused shared background rate. * Allow bounded refresh-ahead discovery while unrelated shared page-refill rows exist, while retaining the exact per-URL pending-refill guard so the same page is never probed or queued twice. * Preserve the timestamp of the last completed scan when a priority or capacity gate skips discovery, instead of treating a skipped attempt as a completed scan. * Reuse one capped retry-backoff contract for transient public-probe failures and durable enqueue failures, with executable scheduling, same-URL pending, and escalating-backoff fixtures. = 2.59.11.51 = * Replace the ambiguous `array|null` Varnish invalidation queue return with explicit direct, queued, unavailable, and failed decision modes and typed reasons. * Bound queue-failure fallback to at most 20 canonical URLs and 20 estimated endpoint requests when durable storage is unavailable or accepts zero rows, leaving the remainder to the declared TTL fallback instead of blocking the WordPress request. * Refill only URLs that were actually invalidated, expose queue-failure and TTL-deferred accounting in production results, and keep partially persisted batches on the durable queue without duplicate direct execution. * Add executable fixtures for URL and endpoint thresholds, duplicate canonicalization, partial persistence, foreground ownership, zero background rate, queue storage failures, and both targeted and site-known-URL callers. = 2.59.11.50 = * Add versioned page-lifecycle proof fields to persistent LCP mappings and verify a bounded set of old locked page URLs through the existing scheduled cleanup job. * Remove exact LCP rows and manual-selector state before a post is trashed or permanently deleted, while resetting orphan evidence after saves, restores, and real locked browser observations. * Delete URL-only mappings only after two consecutive `404`/`410` responses, stale mappings after repeated permanent `301`/`308` redirects, and treat temporary redirects, transport failures, and server failures as non-destructive evidence. * Use no-follow HEAD probes with a one-byte GET fallback, compare-and-swap lifecycle updates, and executable fixtures for missing pages, redirects, races, hook timing, bounded selection, and terminal row accounting. = 2.59.11.49 = * Classify browser-observed LCP winners through one canonical viewport policy as universal, viewport-specific, or ambiguous. * Apply `fetchpriority="high"`, eager image loading, and video preload promotion only when all three viewports confirm the same resource and one specific element identity. * Match universal image, video, and poster candidates by their stored selector so duplicate elements using the same URL are not promoted together. * Preserve one unscoped image preload for universal winners and media-scoped preloads for viewport-specific or incomplete mappings, with executable image, srcset, video, poster, background, and duplicate-winner fixtures. = 2.59.11.48 = * Preserve link-level media conditions on hoisted `@import` rules, including imports qualified by `layer()` and `supports()`. * Reject a CSS source run when link media and import media require an intersection that cannot be represented without changing semantics, instead of emitting an unconditional import. * Canonicalize compatible UTF-8 `@charset` declarations once and reject non-UTF-8 or conflicting charset declarations before any bundle file is committed. * Carry link media through the leftover bundle path and add executable fixtures for media qualifiers, conflicts, unsafe media, comments, UTF-8 aliases, and incompatible charsets. = 2.59.11.47 = * Consolidate leftover and generated font-mix stylesheets only inside maximal contiguous runs of eligible stylesheet links, preserving every skipped stylesheet boundary. * Replace global URL-based source removal with ordinal link-position plans so duplicate URLs and disjoint runs retain their original document identity and cascade position. * Generate one bundle per eligible run, assign unique bundle and delayed-font element IDs, and keep isolated eligible stylesheets unchanged when no adjacent partner exists. * Add executable run-planning and HTML rewrite fixtures for nonlocal, media, non-stylesheet, duplicate-URL, multiple-run, and delayed font-mix cases. = 2.59.11.46 = * Store a deterministic per-source CSS bundle fingerprint using the source URL, hashed canonical filesystem identity, modification time, and byte size. * Reject CSS manifest entries when a source changes, disappears, resolves to a different local file, or predates the fingerprint contract. * Invalidate the CSS bundle manifest on theme switches and Customizer saves before the affected frontend URLs are purged. * Add executable freshness fixtures for unchanged, modified, missing, and legacy source states without exposing server filesystem paths or adding upgrade migrations. = 2.59.11.45 = * Keep inline scripts that call `document.write()` or `document.writeln()` on the synchronous HTML execution path, including direct, optional-chaining, and quoted bracket-property variants. * Extend the first-party delayed-loader ready hold to `jQuery.ready.then()` while preserving its returned Deferred chain and restoring both jQuery ready registration surfaces after the lane flush. * Preserve ordinary inline-script delay eligibility, first-party execution order, CSP attributes, and the existing automatic trigger policy. * Add permanent PHP and executable JavaScript regression fixtures for document-stream-write exclusions, jQuery ready ordering, promise continuation, exact hook restoration, and one-time flushing. = 2.59.11.44 = * Complete the full roadmap regression candidate with release-identity, Media Replacement schema-parity, package-directory, REST/UI, and generated-artifact assertions. * Align the public Media Converter replacement schema constant with the active schema version 11 used by the dedicated replacement manager. * Refresh the translation-template project version, add the WordPress readme changelog section, and add direct-access guards to the remaining package directories. * Clear the pending Media Conversion background cron hook during normal plugin deactivation, matching uninstall and full-cleanup behavior. * Re-run the permanent cache, object-cache, warm-up, ESI, Media Replacement, LiteSpeed, and JavaScript regression suites without changing their accepted runtime contracts. = 2.59.11.43 = * Register the ESI and live Google Fonts template-enhancement callbacks only immediately before template inclusion and only when the current request can use them, instead of forcing WordPress full-output buffering on every frontend response. * Force ESI buffering only when at least one fragment is registered, when another feature already requires the same buffer, or when an integration explicitly opts into late-registration compatibility. * Preserve page-cache STORE, Runtime JavaScript scan, Google Fonts, upstream-filter, WooCommerce, and registered-fragment transformation paths while allowing no-fragment bypass requests to stream. * Return the registered inline fallback when the expected WordPress template buffer did not start, and extend the permanent parity harness with selective callback, late-registration, upstream-buffer, and no-buffer fixtures. = 2.59.11.42 = * Add a deterministic ESI registry has_fragments/count contract and snapshot registered fragment state at the first template-enhancement buffer decision. * Record the effective buffering reason for Runtime JavaScript scans, page-cache STORE, Google Fonts cleanup, ESI, upstream filters, and no-buffer decisions. * Track bounded registration hooks, init timing, and fragments registered after the first buffer decision, and expose current/late counts in request-profile checkpoints. * Preserve the existing ESI-enabled full-buffer behavior and verify byte-identical fragment definitions, rendering, fallbacks, and signed tokens while extending the permanent parity harness. = 2.59.11.41 = * Enforce a versioned LiteSpeed query-URL operation contract: native retrieval bypass, no native storage, no exact query purge, no query refill, and no base-URL aliasing. * Reject non-empty query strings before LiteSpeed URL normalization so `/product?filter=red` can no longer purge or refill `/product`. * Partition targeted invalidation inputs, report skipped query/invalid URLs, and enqueue only exact local queryless URLs into the LiteSpeed refill pipeline. * Skip query URLs as not applicable in site-warm and targeted refill paths, expose the operation contract in diagnostics/UI, and extend the parity harness with executable query-operation fixtures. = 2.59.11.40 = * Add a versioned LiteSpeed query cache-key proof bound to the canonical query-policy fingerprint. * Prove with executable fixtures that preserving native query order fragments equivalent URLs, while dropping allowed keys aliases distinct values; native key modifiers therefore cannot represent UltraCache canonical key ordering, structured-value ordering, and RFC3986 encoding. * Recompute the proof in runtime and advanced-cache configuration, project its fingerprint/status into managed LiteSpeed rules, diagnostics, and exact-invalidation results, and ignore forged embedded proof state. * Keep the blanket LiteSpeed query-string bypass active and do not install CacheKeyModify or cache-key-mod directives. = 2.59.11.39 = * Add a versioned canonical query-string cache policy with normalized effective allowlist, immutable/configured hard-blocked keys, and a stable behavior fingerprint. * Make the page-cache engine and embedded advanced-cache runtime consume the same policy projection while preserving the existing query cacheability behavior. * Project the same policy fingerprint into managed LiteSpeed rules, diagnostics, and exact-invalidation results without enabling LiteSpeed query-string retrieval yet. * Extend the parity harness with engine/drop-in policy fixtures, order-independent fingerprint checks, hard-blocked allowlist filtering, and projection-only LiteSpeed assertions. = 2.59.11.38 = * Add a dependency-free CLI parity harness that executes the real engine helpers and extracts the real advanced-cache query and Accept implementations instead of duplicating their logic in tests. * Cover host directory normalization, query canonicalization, HTML image buckets, private ESI cookies, manual warm-up REST/UI actions, Media Queue wait metadata, and Media Replacement live encoding/compare-and-swap invariants. * Add a generated runtime object-cache conformance fixture for forced reads, add/replace, numeric operations, non-persistent groups, suspended additions, multiple-key APIs, cloning, deletion, and runtime flush semantics. * Add executable dashboard job-runner fixtures for bounded queue-build backoff, progress-token reset, resumable stalls, and exactly-once exclusive lease pause behavior. = 2.59.11.37 = * Add a bounded, deduplicated in-memory admin error history with debug-only console reporting for non-fatal JavaScript failures. * Surface exclusive job pause, failure, and release lease errors with actionable warning notices while ensuring release exceptions cannot leave the dashboard busy state stuck. * Record job persistence, lifecycle refresh, Media Library Replacement status, and cache/dashboard refresh failures without interrupting successful primary operations. * Classify harmless browser storage, focus, and scrolling failures explicitly and remove every empty catch block from the administrator JavaScript modules. = 2.59.11.36 = * Bind Delete Originals start-confirmation tokens to the active job, verified generation, WordPress user, and creation time, with a ten-minute lifetime. * Consume the confirmation token once when the first destructive chunk starts, then require the recorded generation authorization and current replacement lease for pause, resume, and retry. * Omit expired or wrong-user Delete Originals tokens from status responses and reject token replay, generation drift, and exact-expiry-boundary use before any original file is touched. * Allow WP-CLI Delete Originals resume invocations to continue without a consumed start token while retaining the existing resumable database and Theme CSS confirmation behavior. = 2.59.11.35 = * Added SHA-256 fingerprints to Media Library replacement registry rows so Delete Originals detects same-size content changes. * Centralized cleanup row validation across Preview, failed-row recovery, and the active Delete Originals runner. * Replaced string-prefix uploads checks with canonical filesystem containment. * Removed the superseded Cleanup Apply REST, facade, manager, API, and admin UI deletion path. = 2.59.11.34 = * Resolve serialized, JSON, or raw database encoding from the value read immediately before Media Library replacement apply, verification, and rollback instead of trusting only the earlier Preview flags. * Preserve valid serialized string lengths and JSON structure when a database row changes format between Preview and Apply. * Use byte-exact compare-and-swap database updates so a concurrent writer cannot be overwritten between the UltraCache read and write. * Apply the same compare-and-swap protection to post-write recovery, rollback, and serialized-value repair operations. = 2.59.11.33 = * Return explicit media queue-building wait state, retry timing, build metadata, and a stable progress token when the queue has no ready items but its rebuild is incomplete. * Prevent the dashboard job runner from immediately repeating empty unchanged batches by using cancellable bounded exponential backoff, cursor/progress-token checks, a no-progress timeout, and a hard iteration cap. * Pause stalled media jobs in a resumable state instead of generating an unbounded REST polling loop while another rebuild worker holds the lock or the rebuild cannot advance. * Preserve compatibility with older batch payloads by inferring queue-building waits from the existing queue status. = 2.59.11.32 = * Keep the filtered private ESI HTTP Cookie header in raw wire format while populating $_COOKIE with one-pass raw URL-decoded values that match PHP request semantics. * Reject encoded control characters after decoding, preserve literal plus signs, and keep the first duplicate cookie value as PHP does. * Reuse the same bounded cookie parser for production private fragments and the Varnish private-transport probe. * Correct the private-fragment documentation so WordPress login-dependent renderers explicitly declare and transport the wordpress_logged_in_ cookie prefix. = 2.59.11.31 = * Allow the implemented dashboard manual warm-up cancel action through REST schema validation so the UI request reaches the ownership-checked cancellation handler and releases foreground priority. = 2.59.11.30 = * Scope Redis, APCu, and Disk request-local fallback markers by the actual runtime cache scope so one multisite blog cannot affect the same group/key in another blog. * Route runtime flush and deprecated reset operations through the active backend so request-local fallback tracking is cleared with the values it describes while global reset state remains preserved. * Keep group-level fallback cleanup limited to the current blog/global scope instead of clearing unrelated scoped state. * Make the Runtime backend ignore forced persistent refreshes and return its request-local value because it has no persistent storage layer. * Complete the object-cache conformance matrix across Runtime, Redis, APCu, SQLite, and Disk, including single-site, multisite, multiple APIs, non-persistent groups, expiry, fallback recovery, and concurrency regressions. = 2.59.11.29 = * Serialize Disk add, replace, delete, and numeric mutations with global, group, and striped per-key file locks while retaining atomic temporary-file rename writes. * Prevent concurrent Disk add winners, replace/delete resurrection, and lost numeric updates; preserve the original absolute expiry during numeric mutations. * Keep Disk reads concurrent through shared locks, make group/full flushes wait for active operations, and preserve the internal lock directory across flushes. * Give Disk cache groups collision-resistant slug-plus-hash directories so distinct names such as a/b and a-b no longer share one file namespace. * Treat unsupported Disk values as request-local cache entries without fatal serialization errors or stale persistent files, and synchronize dirty numeric fallback state after storage recovers. * Enforce Disk payload and signed-envelope size limits before writing unreadable cache files. * Extend the Disk backend diagnostic to verify file locking, atomic rename, readback, and cleanup rather than raw read/write alone. = 2.59.11.28 = * Make APCu add() use atomic apcu_add() so concurrent requests cannot both add the same persistent key. * Serialize APCu set, replace, delete, and signed numeric mutations with bounded token-owned per-key locks, stale-lock expiry, and ownership-safe release. * Preserve APCu numeric TTLs, prevent replace/delete resurrection and lost numeric updates, and keep in-flight writes bound to the namespace/group generation they locked. * Track request-local APCu fallback values until a later successful mutation synchronizes them, while removing stale persistent envelopes after failed or unsupported replacement writes. * Require and probe APCu atomic primitives, including apcu_cas(), before reporting the backend as available. = 2.59.11.27 = * Make Redis incr() and decr() use bounded WATCH/MULTI/EXEC transactions so concurrent numeric mutations accumulate instead of overwriting each other. * Preserve the existing Redis expiry window during numeric updates instead of silently removing the key TTL. * Retry transaction conflicts against the latest signed Redis payload and return false after a bounded five-attempt limit without overwriting the committed value. * Track request-local Redis fallback values as authoritative until a later successful transaction synchronizes the accumulated value back to Redis. * Reuse one signed Redis payload decoder for normal reads and transactional numeric mutations. = 2.59.11.26 = * Make Redis add() use an atomic conditional SET NX write so concurrent requests cannot both add the same persistent key. * Make cold Redis replace() use SET XX so a key deleted concurrently is not recreated by an unconditional write. * Preserve request-local fallback semantics when Redis is unavailable or a value cannot be serialized, and remove stale persistent values for unsupported replacements. * Centralize signed Redis payload encoding and keep conditional TTL writes aligned with the existing Redis envelope and expiry contract. = 2.59.11.25 = * Reject invalid cache keys consistently across the public object-cache API while preserving integer zero as a valid key. * Return false when delete() targets a missing key and keep delete-multiple results aligned with actual cache existence. * Keep single-site cache scope unchanged during switch_to_blog(), preserve global runtime groups during reset(), and retain multisite isolation. * Treat entries expiring at the current second as expired across shared payload checks and SQLite cleanup, add, read, and replace paths. * Keep failed SQLite add() calls from creating request-local values when no authoritative existing row can be recovered. * Preserve SQLite expiry during request-local numeric synchronization while matching WordPress zero-coercion and floor-at-zero behavior. = 2.59.11.24 = * Make incr() and decr() use an existing request-local numeric value before forcing a persistent read. * Keep numeric mutations operational in the runtime backend and after Redis/APCu persistent-write fallback. * Preserve non-persistent-group numeric behavior and the existing decrement floor at zero. * Retain SQLite atomic numeric mutation for synchronized/cold persistent values while recovering runtime-only or divergent request-local counters through the normal write path. = 2.59.11.23 = * Read forced gets from the request-local store for non-persistent groups instead of reporting a false miss. * Preserve existing request-local keys when add() or replace() checks persistent storage, including runtime-only fallback values. * Limit wp_suspend_cache_addition() to add() and return false without writing while additions are suspended; keep set() and replace() operational. * Make SQLite replace runtime-only values through the normal write path while retaining its conditional persistent replace for uncached keys. = 2.59.11.22 = * Use one canonical page-cache host-directory normalization contract in the engine and the generated advanced-cache drop-in. * Preserve valid short and multi-label hostnames and punycode labels without WordPress filename-extension rewriting or hyphen collapsing. * Normalize trailing-dot hosts consistently and preserve explicit request ports in the early drop-in cache key. * Restore pre-WordPress page-cache hits for affected host and authority forms. = 2.59.11.21 = * Reused ultracache_server_value() for Varnish canary and ESI cookie server inputs. * Made the LCP manual-selector upsert and bounded warm-queue hash query expose every prepared-statement argument explicitly. * Replaced the discouraged mt_rand() fallback with wp_rand(). * Applied the existing controlled diagnostic HTML output contract to the Varnish canary response. * Shortened the WordPress.org short description to remain within the 150-character limit. = 2.59.11.20 = * Fix integration-card headings, including Varnish Cache, using the active dashboard text token instead of a hard-coded white color. * Preserve the existing light heading in dark mode while rendering a readable dark heading on the WordPress-native white card background. = 2.59.11.19 = * Removed the pre-run CSS/font directory inventory from `warm_html_all_css`; optional filesystem reporting now runs only after the canonical warm-up has completed. * Added an immediate preparation message before the progress bar so WP-CLI execution is visible from command entry. * Made generated asset traversal exception-safe, including unreadable nested directories. * Reported final inventory limitations explicitly without replacing or aborting the per-URL HTML/CSS warm-up result. = 2.59.11.18 = * Replace the misleading final homepage-only CSS message with a site-wide WP-CLI report built from the canonical per-URL warm pipeline results. * Report completed, skipped, and failed HTML URLs separately; report per-page CSS bundles built, reused, skipped, and failed, plus stylesheet and byte totals for newly built bundles. * Inspect the generated cached HTML variants for main page bundles, leftover bundles, font-mix bundles, font-css, optimized-css, and localized Google Fonts references, including a dedicated homepage verification line. * Report post-run manifest validity and generated asset inventory with new-file deltas for main, leftover, font-mix, delayed-font, font-css, optimized-css, Google Fonts CSS, and Google Fonts WOFF2 assets. * Remove the redundant second homepage CSS rebuild after the full-site crawl; the homepage is now verified from the same canonical crawl result as every other URL. * Raise foreground UI/WP-CLI HTML and CSS-source loopback timeouts from 10 to 60 seconds for heavy pages while keeping cron, visit, and other background profiles at 10 seconds. = 2.59.11.17 = * Restore Flush All Cache when Varnish inclusion is enabled by calling the authoritative Ultra_Cache_WP Varnish runtime helper from the REST permission callback. * Keep the existing infrastructure capability requirement for active Varnish flushes without duplicating Varnish configuration logic inside the REST API class. = 2.59.11.16 = * Normalize Varnish capability rows to Supported, Not supported, or a mode-specific Unavailable state; remove ambiguous Not verified and Not tested capability labels. * Show HTTP PURGE, VCL contract, soft purge, origin revalidation, and stale-while-revalidating as unavailable in Admin/BAN mode while preserving supported Admin BAN, flush, and ESI capabilities. * Derive Flush scope and ESI capability status directly from effective runtime support instead of displaying raw unavailable registry states. * Extend Test Varnish with an HTML-variant proof that runs the existing canonical page warm pipeline, including its existing Varnish invalidation and refill stages, then verifies the active orig, WebP, and AVIF public objects. = 2.59.11.15 = * Clarify Varnish diagnostics by showing HTTP PURGE and VCL contract rows as not used or not applicable in Admin mode instead of implying missing capability. * Show Admin endpoint verification, non-expiring Admin proofs, unverified capabilities, and untested HTML variants with mode-appropriate labels. * Add Help FAQ guidance that recommends Admin/BAN when available and verified, with HTTP PURGE as the practical fallback when the host exposes no admin endpoint. * Add the verified generic full-site WP-CLI warm-up command using the existing HTML, Separate CSS Bundle, Varnish/LiteSpeed, and orig/WebP/AVIF pipeline. = 2.59.11.14 = * Fixed authenticated WP-CLI and dashboard warm loopbacks being rejected as `invalid-internal-control` when they carried the valid warm runtime token without a force-revalidate flag. * Fixed authenticated internal CSS bundle source requests using the same runtime-control contract. = 2.59.11.13 = * Refactor both bundled CWP templates into ready-to-install per-domain templates with no embedded secret, token placeholder, disabled contract, or manual post-download edit. * Retain exact normalized host matching, local-direct exact PURGE, canonical AVIF/WebP/original HTML variants, public ESI, the recommended private/WooCommerce ESI handshake, object host/URL metadata for Varnish admin BAN, separate grace/keep windows, and cache observability. * Keep advanced exact, batch, HTML-only, and entire-host invalidation on UltraCache's existing Varnish admin transport instead of duplicating authentication inside each domain template. = 2.59.11.12 = * Emit an explicit per-endpoint result from the single-endpoint Varnish canary and persist that result directly into the authoritative capability registry. * Make endpoint-registry status reads side-effect free so diagnostics, planners, runtime enablement checks, and configuration projections cannot rewrite or erase a verified proof. * Keep capability proofs attached to configured endpoints while runtime enablement remains a separate execution gate, and preserve valid proofs across temporary disable/read cycles. * Treat configuration fingerprint mismatches as read-only projections until a new explicit test or capability writer replaces the stored proof. = 2.59.11.11 = * Pass the exact normalized Varnish settings snapshot used by Test Varnish through behavior execution, endpoint-registry synchronization, profile sanitization, and persistence. * Remove the 2.59.11.10 reader-side proof backfill and restore the registry reader to validation-only behavior. * Prevent post-test settings re-reads from dropping or invalidating a successful endpoint proof before it reaches the authoritative capability registry. = 2.59.11.09 = * Fixed the public upgrade reset to recreate the disposable warm-up queue without running legacy row consolidation. * Preserved the existing one-time Flush All flow and user settings while preventing MariaDB ambiguous-column errors during upgrade. = 2.59.11.08 = * Promote the integration-hardened warm-up architecture to the final validation candidate without changing runtime behavior from 2.59.11.07. * Re-run the complete atomic coordination, ownership, stale-worker fencing, full-site plan, shared rate, read-only status, public upgrade reset, canonical queue, targeted-work, frontend-visit, Varnish, LiteSpeed, CSS, and LCP regression suite against the release tree. * Verify release identity, unchanged schemas and public API, prepared-SQL compliance, plugin-root ZIP packaging, extracted-tree equality, and deterministic validation evidence before controlled live-server testing. = 2.59.11.07 = * Persist every configured Varnish and LiteSpeed refill requirement in the same canonical page_warm row as HTML, for both targeted work and newly discovered full-site URLs. * Keep frontend HIT satisfaction limited to the HTML stage so CSS, LCP, Varnish, and LiteSpeed requirements remain pending until their canonical stages complete. * Replace the targeted Varnish sibling upsert and redirect stage loop with one normalized required_stages upsert, preventing duplicate coalesced/upgraded metrics and preserving LiteSpeed stages across canonical redirects. * Make Varnish and LiteSpeed refresh-ahead declare only their own external-cache stage, while ordinary affected-page work adds each enabled targeted refill policy to the shared URL row. * Make background execution follow the canonical required_stages contract instead of silently enabling external-cache work from a generic targeted context, without changing ownership, plan, rate, queue schema, or scheduling architecture. = 2.59.11.06 = * Add one version-gated public upgrade reset from the WordPress.org/SVN 2.59.10.01 baseline while treating later private development warm runtime as disposable. * Preserve the complete UltraCache settings option, discard legacy warm queues, owners, leases, cursors, retries, generations, and private warm decision/plan/rate payloads, then recreate the canonical queue and clean atomic coordination records. * Run exactly one canonical Flush All Cache with the plugin_update reason, suppress automatic warm scheduling during the purge, and coalesce one fresh after-flush full-site plan only when the saved setting and background rate enable it. * Make the transition resumable and idempotent with a dedicated upgrade lock, flushed/initialized phases, and a completed target marker; fresh installations are marked complete without an unnecessary cache flush. * Avoid migrating transient queue rows through private development schemas by recreating the disposable warm queue directly at schema 17. = 2.59.11.05 = * Consolidate dashboard, REST, and WP-CLI warm-up status through one read-only snapshot built from warm_decision, warm_plan, warm_rate, legacy lifecycle compatibility fields, and bounded canonical queue aggregates. * Add read-only lock and state readers that never create or upgrade schema, and display expired foreground or cron leases in memory without recovery writes. * Derive pending and processing totals from the existing aggregate queue query, use at most one LIMIT 1 current-activity lookup, and avoid loading URL result sets regardless of queue size. * Preserve the complete 2.59.11.04 status contract while adding the authoritative warmRate projection and reusing already-read decision, rate, lifecycle, and schedule data for worker diagnostics. * Keep Varnish refill-worker diagnostics read-only by accepting the consolidated status context instead of re-reading or recovering warm runtime state. = 2.59.11.04 = * Move the persisted real-minute background URL allowance into one revisioned atomic warm_rate record with window, claimed, configured, and effective limits. * Make WP-Cron, kickoff, WP-CLI/server-cron ticks, REST ticks, canonical page stages, persistent Varnish work, and LiteSpeed refill share the same remaining minute budget. * Claim only executable URL slots through compare-and-swap so concurrent invocations cannot exceed the configured rate while interrupted workers may conservatively under-use a minute. * Keep enqueue, Flush All, warm start, settings synchronization, and repeated same-minute invocations from resetting consumed slots or granting a second allowance. * Keep rate 0 as a true paused state that leaves queued work pending and removes recurring or kickoff warm events instead of creating a reschedule storm. = 2.59.11.03 = * Move full-site plan identity, discovery cursor, source batch, scheduled selection limit, and mixed-workload fairness pointer into the revisioned atomic warm_plan record. * Derive full-site selected, processed, outcome, and remaining counts from canonical queue membership instead of persisting duplicate counters. * Guard discovery-batch commits and cursor advancement with exact compare-and-swap revisions so stale writers cannot move discovery backward. * Complete and release the full-site plan independently of unrelated targeted work or retries, allowing targeted automation to continue. * Reattach a paused active plan when the background rate is re-enabled, preserving the same plan ID, committed cursor, batch, limit, and fairness state. = 2.59.11.02 = * Bind UI, WP-CLI, and cron worker heartbeats to the exact authoritative source, token, and generation, with every explicit start or resume rotating to a fresh execution token. * Revalidate ownership before per-URL claims, before HTML/CSS/LCP/Varnish/LiteSpeed work, after network/cache operations, and immediately before canonical queue result commits. * Release stale cron and persistent Varnish row claims back to pending work instead of recording completed stages after foreground preemption or lease loss. * Fence CSS bundle file and manifest writes, suppress stale Varnish/LiteSpeed result persistence, and preserve the existing atomic frontend-visit stage merge. = 2.59.11.01 = * Moved UI, WP-CLI, and cron warm-up ownership to one revisioned atomic warm_decision state record. * Made the newest successful UI or WP-CLI start/resume the authoritative foreground owner while cron always yields to a valid foreground lease. * Routed foreground and cron acquire, heartbeat, pause, release, expiry, and recovery through the shared decision record. * Kept full-site plan and background-rate persistence on the existing legacy backend for their dedicated roadmap versions. = 2.59.11.00 = * Upgrade the shared UltraCache locks table to schema version 2 with explicit lock/state record types, revisions, update timestamps, and a type/expiry index. * Add generic persistent state helpers for named reads, atomic creation, revision-guarded compare-and-swap updates, bounded mutation retries, named deletion, and explicitly requested record reads. * Restrict every existing lock acquire, read, renew, release, and expired-row cleanup query to lock records so persistent state rows cannot be mistaken for or deleted as leases. * Preserve the existing option-backed warm runtime and ownership behavior; the new atomic backend is foundation only in this version. = 2.59.10.99 = * Add a dedicated warm coordination access trait as the only persistence boundary for legacy cron, dashboard, WP-CLI, and cache-flush generation state. * Separate legacy state normalization into explicit decision, full-site plan, and shared-rate helpers while preserving the existing option-backed runtime behavior. * Add an executable field-ownership inventory for cron and foreground state so the later atomic storage migration has a verified, bounded contract. * Keep queue schema, ownership semantics, UI and WP-CLI behavior, cron scheduling, targeted warm-up, frontend visits, Varnish, and LiteSpeed integration unchanged. = 2.59.10.98 = * Enforce Background warm pages per minute as one persisted real-minute URL ceiling instead of granting the full configured rate to every cron tick invocation. * Serialize minute-window claims across kickoff events, WP-Cron, real server cron, and explicit background tick calls so overlapping invocations cannot multiply the allowed Varnish and page-pipeline work. * Preserve the shared Varnish/page budget from 2.59.10.97 inside the single claimed minute window, including explicit pages-per-minute overrides. * Defer duplicate same-minute invocations to the next minute boundary without clearing queue rows, full-site discovery, mixed-workload fairness, retries, or ownership state. * Prefer conservative under-use after an interrupted tick over allowing a second invocation to overload the server in the same minute. = 2.59.10.97 = * Enforce one shared background URL budget per cron tick across persistent Varnish invalidation and canonical page automation. * Subtract Varnish URLs already processed in the tick from the remaining page-warm selection budget instead of allowing both workers to consume the full configured rate independently. * Keep the configured Background warm pages per minute value unchanged in worker state and diagnostics while using only the remaining per-tick budget for full-site discovery and mixed full-site/targeted queue selection. * Apply an explicit cron-tick pages-per-minute override consistently to auxiliary Varnish work and targeted/full-site page selection for that same tick. * When queued Varnish invalidation consumes the complete tick budget, preserve all page/full-site state and continue it on the next scheduled tick instead of treating the worker as configuration-paused. = 2.59.10.96 = * Apply Background warm pages per minute to the persistent Varnish invalidation worker instead of processing a fixed batch of up to 100 URLs on every cron tick. * Keep queued Varnish invalidation paused when the shared background rate is 0, without repeatedly scheduling a worker that cannot execute page automation. * Recheck UI/WP-CLI foreground ownership before auxiliary invalidation work, after acquiring the shared lock, and between bounded Varnish network groups. * Release unprocessed Varnish queue claims immediately when a newer foreground owner appears, preserving retry state and allowing the dashboard or WP-CLI warm-up to take priority without waiting for lease expiry. = 2.59.10.95 = * Recheck the authoritative warm-worker state after acquiring the shared start lock, preventing concurrent after-flush or after-cleanup requests from replacing the full-site plan created by the first request. * Preserve the first plan's membership, discovery cursor, Scheduled / Cron warm limit, source ordering, and progress when a second start request passed the earlier advisory state check. * Recheck UI/WP-CLI foreground ownership inside the same lock before resetting full-site state, so a foreground warm-up that starts during the pre-lock window still retains priority over background automation. * Keep the existing pre-lock checks as a low-cost fast path while making the locked checks authoritative for all state-changing start operations. = 2.59.10.94 = * Preserve `scheduled-full-site-complete` when a terminal canonical URL starts a later targeted update, import, LCP, CSS, or external-cache lifecycle during the same active full-site plan. * Prevent terminal-row reuse from demoting an already processed full-site member back to `scheduled-full-site`, reducing processed progress, or counting the URL a second time when the targeted rerun completes. * Keep the persisted full-site success/skipped/error outcome unchanged while resetting only the independent targeted lifecycle stages, claims, retries, position, and source context. * Strip an incoming unprocessed full-site marker before restoring completed membership, keeping the canonical context set mutually consistent even under defensive duplicate enqueue paths. = 2.59.10.93 = * Alternate full-site and targeted canonical URLs across background ticks when Background warm pages per minute is 1, preventing either workload from starving behind the other. * Start each new mixed full-site plan with its highest-priority selected URL, preserving homepage-first source ordering before alternating to targeted work. * Persist the next mixed-workload class in the shared worker state so real cron invocations, restarts, and ownership handoffs retain deterministic fairness. * Continue processing the only available workload immediately when the other class has no executable URL; background rates of 2 or more retain the existing bounded split. = 2.59.10.92 = * Advance full-site URL discovery while targeted update/import work remains pending instead of waiting for the complete shared queue to become empty. * Reserve a bounded share of each background tick for selected full-site members while continuing targeted canonical work in the same gentle worker. * Advance the full-site cursor when the current selected batch is accounted for, even when unrelated targeted URLs remain queued. * Complete and release full-site membership independently once discovery and selected URLs finish, then continue remaining targeted automation without resetting or deleting it. = 2.59.10.91 = * Allow a new full-site background warm-up plan to start when the shared automation state is currently active with targeted update, import, LCP, CSS, or external-cache work. * Treat only an already active and fresh `full_site` workload as an existing full-site plan; a targeted workload no longer suppresses Warm full site after Flush All Cache or scheduled cleanup. * Preserve all existing canonical targeted rows while resetting only the full-site discovery cursor, selected-URL limit, and plan progress for the new full-site workload. * Keep mixed targeted and full-site work on the same shared queue and background execution rate without expanding the Scheduled / Cron warm limit. = 2.59.10.90 = * Preserve full-site membership during targeted enqueue from the authoritative current canonical row instead of injecting a marker captured by an earlier membership lookup. * Prevent a targeted enqueue that overlaps full-site plan completion or replacement from resurrecting `scheduled-full-site` or `scheduled-full-site-complete` after membership cleanup has removed it. * Continue preserving selected or completed membership when it still exists in the database, including visit/worker completion races handled by version 2.59.10.89. * Avoid loading the complete active full-site membership lookup for ordinary targeted enqueue requests; cross-batch discovery still uses the lookup for actual full-site planning. = 2.59.10.89 = * Preserve an already completed full-site membership when a targeted enqueue races with frontend-visit or worker completion of the same canonical URL. * Resolve the terminal-row membership transition atomically inside the canonical upsert instead of trusting an earlier full-site membership snapshot. * Prevent a stale `scheduled-full-site` snapshot from replacing `scheduled-full-site-complete`, reverting processed progress, or causing the URL to be counted again by the active plan. * Keep targeted lifecycle reset, stages, priority, retries, and persisted full-site outcome unchanged. = 2.59.10.88 = * Preserve stages satisfied by a real frontend visit after a newer request marks an actively processing canonical URL for rerun. * Track pending-rerun stage satisfaction separately from the outgoing worker lifecycle, then promote only that authoritative set when the claim is released, completed, or recovered after lease expiry. * Prevent the outgoing worker from clearing valid HTML, CSS, LCP, Varnish, or LiteSpeed progress that belongs to the pending rerun while still discarding completion inherited from the older lifecycle. * Upgrade queue metadata to version 17 and compact the new fixed-stage set without deleting URLs, claims, retries, full-site membership, or targeted work. = 2.59.10.87 = * Merge frontend-visit stage satisfaction directly against the current canonical `completed_stages` value through an atomic fixed-set union, preventing a stale pre-read from overwriting stages completed concurrently by the active worker. * Evaluate pending-row completion from the current database `required_stages` and merged `completed_stages`, so a concurrently added CSS, LCP, Varnish, or LiteSpeed requirement prevents premature terminal success. * Preserve active processing claims when a visit satisfies another stage, allowing the owning worker to continue from the authoritative merged stage set. * Reconcile the persistent pending-URL hint against the post-update queue state, including a URL immediately reopened by a concurrent enqueue. = 2.59.10.86 = * Always reconcile persistent pending-URL hints against the bounded set affected by queue cleanup instead of inferring per-URL removal from an aggregate deleted-row count. * Prevent duplicate legacy rows from offsetting a concurrent pending-to-processing transition and causing the surviving canonical URL to lose its active object-cache hint. * Keep reconciliation limited to fixed 50-hash batches, preserving bounded memory and database work without scanning the complete warm queue. * Remove the deleted-count shortcut whose equality with unique candidate URLs could not prove that the same URLs were actually removed. * Preserve existing hints when the bounded reconciliation read fails, preferring one later queue lookup over hiding an active canonical URL from visit/worker coalescing. = 2.59.10.85 = * Reconcile persistent canonical pending-URL hints only against the URLs affected by queue cleanup instead of reading every active queue row. * Process candidate URL hashes in fixed 50-item SQL batches so cleanup memory and database work remain bounded on large WooCommerce and WP All Import queues. * Preserve active pending/processing hints when duplicate legacy rows or concurrent status transitions make deleted-row counts differ from unique cleanup URLs. * Keep the zero-query normal path when deleted rows exactly match the captured unique cleanup candidates. = 2.59.10.84 = * Synchronize persistent canonical pending-URL hints whenever full-site membership cleanup or ordinary queue cleanup deletes database rows. * Prevent deleted full-site lifecycle rows from leaving one-week object-cache hints that forced the next PHP-served cache hit to perform an unnecessary queue-table lookup. * Preserve or restore hints for pending/processing rows that survive a concurrent status transition while cleanup runs. * Avoid the reconciliation read on the normal path when the number of deleted rows exactly matches the captured cleanup candidates. = 2.59.10.83 = * Release finished full-site membership from canonical rows even when a targeted reuse of the same URL is actively processing at plan completion or replacement. * Preserve the active processing claim, targeted source contexts, required/completed stages, retry state, and queue position while removing only stale full-site markers and the persisted plan outcome. * Prevent a processing targeted row from carrying `scheduled-full-site` or `scheduled-full-site-complete` into the next full-site plan and suppressing that URL as an apparent duplicate. * Apply the same cleanup when a new full-site plan replaces prior membership, so stale markers cannot survive across plan boundaries. = 2.59.10.82 = * Persist the original full-site terminal outcome independently from the reusable canonical row status, so later targeted update/import lifecycles cannot rewrite historical full-site success, skipped, or error accounting. * Keep processed full-site membership stable while the same URL returns to pending, processing, done, skipped, or error for unrelated targeted work. * Clear the persisted full-site outcome only when the active full-site plan releases membership from a mixed canonical row. * Upgrade queue metadata to version 16 and infer exact outcomes for existing terminal full-site members; already-reused legacy members remain processed with an explicit unknown historical outcome instead of inventing a result. = 2.59.10.81 = * Merge worker-completed canonical stages with stages satisfied concurrently by a real frontend visit through an atomic fixed-set union instead of appending raw CSV strings. * Prevent repeated retries, visit/worker races, and processing-row handoffs from duplicating `html`, `css_bundle`, `lcp_refresh`, `varnish`, or `litespeed` tokens in `completed_stages`. * Preserve every stage already recorded by the active processing claim while keeping terminal and retry state transitions unchanged. * Upgrade queue metadata to version 15 so existing duplicate completed-stage tokens are compacted without deleting URLs, claims, retries, progress, or full-site membership. = 2.59.10.80 = * Treat persisted full-site membership markers as the authoritative selected, processed, success, skipped, and error counters while an active plan is open. * Mark a full-site member processed when a real frontend visit completes every required canonical stage before the background worker claims the URL. * Synchronize full-site progress from canonical membership at status reads and at the beginning of each cron tick without turning dashboard status into a schema-mutating path. * Release completed full-site membership and ordinary plan rows when the empty-queue early completion path finishes a plan, preventing stale members from suppressing URLs in the next full-site warm-up. = 2.59.10.79 = * Merge canonical source contexts token by token when targeted work reuses a pending or processing full-site member, instead of treating a multi-context value as one FIND_IN_SET token. * Prevent repeated updates/imports from duplicating `scheduled-full-site`, `scheduled-full-site-complete`, or targeted source markers on the same active canonical row. * Preserve active pending/processing lifecycle state, stage union, queue position, claims, retries, and full-site membership while applying the bounded context set union. * Upgrade queue metadata to version 14 and compact source-context duplicates already written by earlier multi-context upserts without deleting queue work. = 2.59.10.78 = * Deduplicate full-site warm URLs across the complete cursor plan instead of only inside each discovery batch, so homepage, menu, page, post, and taxonomy sources cannot select the same canonical URL twice. * Keep completed full-site membership rows until the plan finishes, allowing later discovery sources to recognize URLs already selected without storing thousands of hashes in the cursor option. * Count `fullSitePlanned` from exact canonical membership so duplicate source URLs do not consume additional `Scheduled / Cron warm limit` capacity. * Preserve pending or completed full-site membership when targeted update/import work reuses the same canonical URL row during an active plan. * Track completed membership separately so a later targeted lifecycle can rerun the URL without increasing full-site success, skipped, error, or processed counters a second time. * Upgrade canonical queue metadata to version 13 and normalize terminal membership markers without deleting URLs, stages, claims, retries, or targeted contexts. = 2.59.10.77 = * Persist explicit full-site membership on canonical queue rows so later targeted, LCP, CSS, or external-cache coalescing cannot erase their full-site progress identity. * Track full-site selected, processed, success, skipped, error, and remaining counters independently from the shared queue's overall targeted workload counters. * Keep targeted enqueue paths from inflating the active full-site plan's total/progress or overwriting its invocation provenance, including paused LCP work at a background rate of 0. * Upgrade queue metadata to version 12 and mark eligible pending/processing rows from earlier releases without deleting URLs, stages, claims, retries, or progress. * Show full-site processed progress separately from selected URLs and the Scheduled / Cron warm limit in Automation Worker status. = 2.59.10.76 = * Keep `Scheduled / Cron warm limit` immutable when targeted update/import URLs join an active full-site background warm plan. * Preserve the active full-site plan's invocation provenance while canonical targeted rows retain their own source contexts for diagnostics and priority. * Continue counting mixed pending URLs for worker progress without converting targeted work into additional full-site discovery budget. * Complete the limit-ownership separation introduced in 2.59.10.62 for mixed full-site and targeted workloads. = 2.59.10.75 = * Preserve large queued Varnish invalidation work while dashboard or WP-CLI foreground warm-up owns execution, without scheduling a competing background kickoff. * Preserve Varnish and LiteSpeed refresh-ahead stages in the canonical queue while foreground ownership is active; normal foreground-release recovery remains the single handoff path. * Respect Background warm pages per minute for external-cache queue scheduling, so a configured value of 0 stores pending work without repeatedly scheduling an ineligible worker. * Keep external-cache discovery and durable enqueue independent from execution ownership, matching the CSS and LCP foreground-deferral behavior introduced in 2.59.10.73 and 2.59.10.74. = 2.59.10.74 = * Preserve frontend-triggered LCP refresh work when dashboard or WP-CLI foreground warm-up owns execution, instead of replacing the interrupted background worker state with an LCP-only state. * Keep foreground priority limited to execution: the LCP stage is coalesced into the canonical URL row immediately and resumes through the existing full-site or targeted worker after ownership is released. * Preserve full-site discovery cursor, Scheduled / Cron warm limit, selected URL progress, and targeted worker metadata while foreground warm-up is active. * Avoid unscheduling or creating a competing background worker from the LCP observation request; normal foreground-release recovery remains the single handoff path. = 2.59.10.73 = * Preserve frontend-triggered async CSS bundle work when a dashboard or WP-CLI foreground warm-up owns execution, instead of dropping the request before it reaches the canonical queue. * Keep foreground priority limited to execution: the CSS stage is coalesced immediately, remains pending, and resumes through the shared background worker after ownership is released. * Avoid overwriting an interrupted full-site plan or scheduling a competing cron worker while UI/WP-CLI ownership is active. * Keep the existing Background warm pages per minute pause behavior and canonical URL/stage deduplication unchanged. = 2.59.10.72 = * Reset queue position from the incoming request whenever a terminal canonical row (`done`, `skipped`, or `error`) starts a new lifecycle. * Keep pending rows on the earliest coalesced position and preserve an actively processing row's claimed position until its current worker releases ownership. * Prevent a previous targeted terminal error at position 0 from jumping ahead when the URL is later selected by a full-site plan. * Prevent a previous full-site terminal error from delaying a later targeted update that must return to position 0. * Complete the terminal lifecycle reset introduced in 2.59.10.71 so context, stages, retries, claims, results, timestamps, and scheduling priority all belong to the new request. = 2.59.10.71 = * Reset `source_context` from the incoming request when a terminal canonical queue row is reused, so a later full-site warm plan cannot inherit stale targeted/import/LCP priority from an earlier lifecycle. * Preserve existing source context and stage unions while a row is pending or processing, allowing active full-site and targeted requests to continue coalescing without losing ownership or diagnostics. * Keep terminal-row reuse internally consistent by resetting `source_context`, `source_contexts`, stages, retries, claims, and result state as one new queue lifecycle. * Prevent reused full-site rows from being retained by targeted-row preservation rules or reported as targeted Automation Worker work after their previous request already completed. = 2.59.10.70 = * Make canonical warm-queue stage and source-context merges idempotent so repeated updates/import hooks do not append duplicate metadata to the same URL row. * Keep `required_stages` in one bounded canonical set during atomic queue upserts, preventing varchar growth, truncation, or failed coalescing after large WooCommerce/WP All Import bursts. * Keep `source_contexts` as a unique bounded token set during atomic queue upserts while preserving every distinct trigger context needed by diagnostics and pipeline planning. * Upgrade queue schema metadata to version 11 and compact duplicate stage/context values already stored by earlier canonical-queue releases without deleting URLs, claims, progress, retries, or completed stages. * Apply the same set-union semantics to legacy CSS, LCP, and Varnish row consolidation so upgrades cannot recreate duplicate canonical metadata. = 2.59.10.69 = * Preserve the active full-site background warm plan when dashboard or WP-CLI foreground work preempts cron, instead of converting the resumed state into a targeted queue recovery workload. * Resume the same full-site discovery cursor, Scheduled / Cron warm limit, selected URL count, queued canonical rows, and remaining discovery batches after foreground Pause, Cancel, completion, interruption, or lease expiry. * Resume a full-site plan even when its current queue batch finished before foreground ownership was released but additional cursor batches still remain to be discovered. * Keep mixed LCP, targeted, CSS, and external-cache stages inside the preserved full-site worker without allowing deferred LCP recovery to overwrite the full-site state. * Respect Background warm pages per minute after foreground release; a configured value of 0 leaves the preserved full-site plan paused rather than misreporting it as foreground-blocked or targeted work. * Restore missing cron scheduling for the preserved plan through the normal worker-recovery path without clearing canonical queue rows or resetting progress counters. = 2.59.10.68 = * Treat a page-pipeline URL lock collision as retryable deferred work instead of a successful skip, preventing pending CSS, LCP, Varnish, or LiteSpeed stages from being lost when a visit, cron worker, dashboard request, or WP-CLI process already owns the URL. * Preserve a dashboard URL for resume when the REST request returns a coalesced lock result, including non-2xx REST responses, and display the LCP stage in the unified per-page result summary. * Add bounded URL-lock retries to direct WP-CLI warm commands and the dashboard homepage HTML/HTML+CSS actions so transient visit/worker overlap does not become a false success or immediate terminal failure. * Give the dashboard homepage warm actions the same UI foreground ownership, heartbeat, cooperative cron preemption, and release behavior as the full dashboard warm-up flow. * Recover expired UI/WP-CLI foreground leases during normal status reads so a stale browser or CLI session cannot remain displayed as an active Automation Worker blocker until a later cron tick. * Include terminal skipped canonical rows in the existing bounded processed-row retention cleanup so long-running targeted automation does not retain them indefinitely. * Complete the cross-path regression audit for cron, dashboard, WP-CLI, visit integration, canonical stages, Varnish capability gating, scheduled/full-site limit ownership, and update/import coalescing without changing their established configuration ownership. = 2.59.10.67 = * Apply retry budgets and backoff per failing canonical stage so earlier HTML/CSS attempts cannot exhaust later Varnish or LiteSpeed retries. * Reset the effective retry counter when an attempt completes a new stage, while preserving completed-stage metadata so the next attempt resumes only the remaining work. * Represent LCP refresh explicitly in the common pipeline and mark it complete with the successful HTML regeneration instead of repeating it after an unrelated external-cache failure. * Record terminal partial outcomes when HTML or another required stage completed but a later non-retryable stage failed; expose partial and failed lifecycle counts separately. * Recover processing rows with expired leases, missing lease timestamps, or abandoned claims while preserving completed stages and bounded stage state. * Preserve a newer rerun request during stale-lease recovery by resetting obsolete completion state only for that rerun instead of silently discarding the request. * Keep dependency-skipped stages pending for the next attempt while treating documented ineligible or disabled stages as completed/skipped outcomes. = 2.59.10.66 = * Redesign Automation Worker status around the active UI, WP-CLI, or cron owner instead of presenting the background cron worker as the only executor. * Report unique queued URLs separately from canonical HTML, CSS, LCP, Varnish, and LiteSpeed stage operations so external-cache stages no longer inflate the page count. * Distinguish running scheduled warm-up, running targeted work, active UI/WP-CLI warm-up, scheduled full-site or targeted work, retry waiting, configuration pause, recovery, and attention-required states. * Show the current owner, URL, pipeline stage, next retry or worker run, and full-site selected/limit counts when applicable. * Present a paused dashboard warm-up as a resumable session without treating it as an active blocker for background automation. = 2.59.10.65 = * Moved Varnish-specific connection, secret state, capability, runtime, queue, performance, ESI, recent-result, and endpoint proof diagnostics into a dedicated Varnish Diagnostics accordion at the end of the Varnish Cache card. * Removed the duplicate Varnish technical diagnostics section from Advanced Diagnostics while retaining general cross-system diagnostics there. = 2.59.10.64 = * Restore the explicit Varnish Cache on/off switch as a canonical setting, with ON opening the integration accordion and OFF closing it while preserving saved endpoints and secrets. * Separate Varnish enablement from connection completeness so administrators can configure the integration before a working endpoint exists, while runtime invalidation, refill, ESI, shared-cache delivery, performance measurement, and Flush All participation require both states. * Preserve upgrade behavior by enabling the restored switch for installations whose current connection marker already made Varnish active, while retaining an explicitly saved legacy OFF state. * Replace the compact generic accordion header with the standard integration-card hierarchy so the Varnish title and description match the size, weight, color, and spacing used by Automation & Scheduling. * Keep Also flush Varnish Cache in the external/server cache layers card and preserve its saved value independently from the Varnish integration switch. = 2.59.10.63 = * Merge successful frontend cache MISS and stale-revalidation storage into the matching canonical warm row after the response has been released. * Treat the canonical HTML stage as satisfied only when every active orig/WebP/AVIF HTML cache variant exists for the URL. * Let PHP-served cache HIT requests complete matching queued HTML work through a persistent-object-cache URL hint, avoiding a database lookup on ordinary hits and on hosts without a persistent object cache. * Preserve active queue claims while a frontend visit contributes completed stages, and union those stages with the owning worker result instead of overwriting either source. * Resume canonical rows from their stored completed-stage metadata so an already satisfied HTML stage can skip the duplicate loopback request and continue directly with pending Varnish or LiteSpeed work. * Keep CSS bundle and LCP refresh requirements authoritative: pending CSS or LCP work still rebuilds the page through the common backend pipeline even when a previous visit created HTML. * Complete HTML-only pending rows directly from the frontend visit and remove their low-cost pending URL hint without creating a foreground warm-up owner. = 2.59.10.62 = * Apply Scheduled / Cron warm limit only while selecting URLs for an explicit full-site background plan; targeted work from updates, imports, LCP refreshes, media discovery, CSS, and external-cache stages no longer consumes or expands that limit. * Track full-site workload type, selected URL count, and discovery completion separately from total queue processing so a mixed canonical queue can finish every targeted URL while the full-site planner remains bounded. * Preserve existing targeted canonical rows when a full-site after-flush or after-cleanup plan starts instead of clearing pending update/import work. * Stop increasing the configured full-site limit when LCP work or canonical redirects are added; redirect targets replace their selected source URL without changing the selection cap. * Report Scheduled / Cron warm limit independently from the active workload limit so targeted queues correctly expose a runtime limit of zero rather than falling back to the full-site setting. * Add explicit shared-pipeline execution profiles: gentle rate-limited cron work, unthrottled dashboard foreground work, extended WP-CLI foreground work, and bounded single-request visit/revalidation work. * Give cron, dashboard, WP-CLI, and visit profiles separate per-page operation budgets while preserving identical URL eligibility, locking, stage ordering, capability checks, and completion semantics. * Mark dashboard homepage warm actions as UI-profile execution and retain cooperative UI/WP-CLI ownership over the lower-priority cron worker. = 2.59.10.61 = * Coalesce repeated post, WooCommerce object, term-update, and term-assignment hooks within the current request before resolving affected URLs. * Use the official WP All Import start, per-record, and completion actions to accumulate changed post and term identifiers across import requests and release one persistent affected-URL planning batch when the import finishes. * Keep the persistent import batch heartbeat current during long-running imports, flush bounded in-memory chunks every 100 imported records, and recover an interrupted import batch after its lease becomes stale. * Resolve persistent affected changes in bounded 250-post/250-term planner chunks, deduplicate purge and warm URLs before any queue insert, and preserve the canonical one-row-per-URL queue contract. * Preserve immediate post-deletion handling while batching update and taxonomy churn whose final state is available at request/import completion. * Preserve the Warm affected pages after save setting and per-post cooldown while ensuring purge requirements are retained even when a URL is not eligible for warm-up. * Retry a persisted affected batch when canonical queue persistence fails instead of discarding the update work after the page-cache purge. * Debounce the affected-batch cron event, remove it during deactivation, and include the non-autoloaded batch option in normal plugin-data cleanup. = 2.59.10.60 = * Store background page work as one canonical `page_warm` queue row per URL and merge HTML, CSS bundle, LCP refresh, and Varnish requirements into bounded stage metadata. * Route new `css_bundle`, `lcp_refresh`, and large `varnish_invalidate` enqueue requests through the canonical URL row instead of creating competing top-level queue rows. * Consolidate existing pending/error legacy queue rows during the permanent schema upgrade while leaving active processing leases untouched until they finish. * Preserve every contributing source context on the canonical row so affected saves, imports, media discovery, LCP observations, refresh-ahead, and external-cache work remain diagnosable after coalescing. * Make the shared worker derive force-refresh, CSS, LCP, Varnish, LiteSpeed, and targeted behavior from the canonical stage/context metadata rather than the legacy job type alone. * Persist completed canonical stages with the terminal queue result and reset them when a newer request arrives during processing. * Preserve canonical stage requirements when a non-canonical URL is replaced by its verified local redirect target. * Report Varnish queue activity from the canonical Varnish stage while retaining compatibility with any legacy processing invalidation lease that is still draining. * Prevent legacy queue rows from being removed unless their canonical merge succeeds, and finalize the queue schema version only after consolidation completes. = 2.59.10.59 = * Route every dashboard crawler URL through the same complete backend page pipeline already used by cron, WP-CLI, targeted work, and warm-after-flush execution. * Replace the dashboard JavaScript HTML/CSS/Varnish/LiteSpeed stage machine with one bounded REST request per URL; JavaScript now manages only job progress, pause/resume/cancel, logs, and counters. * Renew and verify the dashboard foreground lease from inside the backend pipeline before and after HTML, CSS, Varnish, and LiteSpeed work so a newer UI or WP-CLI owner can preempt cooperatively. * Keep per-URL locking, eligibility checks, retry classification, external-cache capability planning, variant selection, and completion decisions inside the common backend contract. * Remove the obsolete manual-warm page-stage REST route, staged engine entry point, and one-bucket Varnish/LiteSpeed dashboard refill adapters. * Make dashboard completion lines derive from the returned common pipeline stage summary instead of reconstructing external-cache state in the browser. * Preserve the image conversion/media queue as a separate attachment-and-file pipeline; media-triggered affected URLs continue to join the shared page warm queue. = 2.59.10.58 = * Add one foreground warm-up ownership record shared by dashboard and direct WP-CLI warm commands, including source, status, generation, heartbeat, lease expiry, current stage, and current URL. * Apply the agreed priority model: the newest dashboard or WP-CLI warm-up owns foreground execution, while the background cron worker always yields. * Make ownership transfer cooperative: the replaced dashboard or WP-CLI worker stops at its next URL/stage heartbeat instead of continuing with an obsolete token or producing repeated failures. * Preserve the existing cron/automation queue and progress when foreground work starts; foreground priority no longer calls the destructive cron stop path. * Make dashboard Cancel end the foreground session and immediately resume pending background automation instead of storing a paused owner that blocks cron indefinitely. * Make an explicit paused dashboard session retain its resumable state while releasing execution ownership so background automation may continue. * Recover expired foreground leases automatically and reattach pending LCP, targeted page-warm, Varnish, and shared queue work to the background worker. * Give direct WP-CLI warm commands a renewable foreground lease and release it at command shutdown; a newer dashboard or WP-CLI owner causes the older CLI pipeline to yield cleanly. * Report Automation Worker states as Yielding to UI or Yielding to WP-CLI and expose the active foreground owner in the status payload. = 2.59.10.57 = * Remove the redundant Cron Warm Up master switch from Automation & Scheduling and canonical settings while retaining it as a legacy migration-only input. * Preserve upgrade behavior by enabling each autonomous full-site trigger only when both the previous master switch and that trigger were enabled. * Merge REST setting patches into the canonical migrated settings so the first post-upgrade trigger change is applied instead of being overridden by the legacy master value. * Make Warm full site after Scheduled Cleanup and Warm full site after Flush All Cache independent triggers governed by the selected Full-site warm-up sources, Scheduled / Cron warm limit, and background work rate. * Move Stale While Revalidate into the former master-switch position and rename the shared rate control to Background warm pages per minute. * Keep targeted work from saves, imports, LCP refreshes, media discovery, and external-cache refill independent from the full-site triggers while using the shared background rate. * Stop settings saves from clearing or stopping existing targeted background work merely because the removed master switch was off. * Update Varnish warm-after-flush and refresh-ahead policy to use the autonomous trigger and shared background worker availability. = 2.59.10.56 = * Complete the Varnish and shared-automation regression pass across fresh and legacy connection state, generic and contract-capable control paths, single and multi-endpoint capability intersection, expired proof, ESI fallback, queue recovery, and Flush All ownership. * Make targeted affected-page refill consume the current Cron warm pages per minute setting on every worker tick instead of using a hidden five-page rate. * Apply the same central work rate to async CSS bundle rebuilds and page-specific LCP refreshes. * Persist targeted, CSS-bundle, and LCP queue rows as paused when Cron warm pages per minute is 0, avoid scheduling a page worker in that state, and resume through the shared recovery path after the rate is restored. * Verify the Varnish card, external/server cache layer card, Automation & Scheduling ownership, and both bundled CWP templates through the release regression checks. = 2.59.10.55 = * Add a throttled request-lifecycle recovery check that reattaches orphaned shared queue rows and restores missing cron worker schedules. * Recover expired queue leases and stale cron execution locks before resuming automation work. * Serialize cron schedule creation through a database-backed scheduler lock so concurrent requests cannot create duplicate workers. * Add shared automation-worker health to the Automation & Scheduling card with pending, processing, next-run, blocked, paused, recovered, and attention states. * Preserve queued page work when the central Cron warm pages per minute limit is 0 and report that state as paused instead of discarding the queue. * Keep Varnish queue details in Advanced Diagnostics and preserve the simplified Varnish card, central TTL ownership, and external/server cache Flush All ownership. * Leave both CWP Varnish templates unchanged. = 2.59.10.54 = * Reduce the normal Varnish status to four user-facing results: connection, automatic cache clearing, full-site cache clearing, and overall measured performance. * Remove ESI, transport, contract, endpoint-proof, purge-method, runtime-strategy, queue, and raw performance terminology from the normal Varnish status. * Replace technical connection and invalidation warnings in the normal card with short corrective guidance while preserving the full underlying failure evidence in diagnostics. * Add a dedicated Varnish technical diagnostics panel under Advanced Diagnostics with connection policy, shared-cache lifetime, endpoint registry state, effective capabilities, runtime plans, queue state, operation metrics, and bounded performance results. * Add per-endpoint diagnostic details for adapter, reachability, exact-invalidation proof, current capabilities, test time, proof expiry, and the latest failure. * Summarize performance in the normal card from current second-pass latency and visible HIT evidence without exposing the raw measurement matrix. * Preserve automatic runtime behavior, ESI policy, capability proofs, settings ownership, REST behavior, queues, generated drop-ins, and both CWP templates unchanged. = 2.59.10.53 = * Remove the obsolete hidden esiEnabled setting from canonical defaults, validation, persistence-change detection, runtime rendering, REST schemas, dashboard state, lifecycle state, and performance-profile ownership. * Make a configured Varnish connection the only eligibility prerequisite for ESI capability testing; no user-facing or hidden enable switch remains. * Activate public ESI automatically only while the current end-to-end public composition proof is effective across the configured topology. * Activate private/session ESI automatically only after verified session isolation, shared-parent reuse, private-fragment no-store behavior, and onerror containment. * Activate the WooCommerce classic mini-cart ESI adapter automatically only after the private transport proof also verifies the WooCommerce cookie/session carrier. * Preserve inline fallback rendering whenever public, private, or WooCommerce proof is absent, expired, invalidated by configuration changes, or incomplete across a multi-endpoint topology. * Keep Test Varnish as the behavioral source of ESI capability state and preserve the standalone CWP templates unchanged. * Canonicalize legacy settings by dropping esiEnabled during normal settings sanitization without adding one-off migration or cleanup code. = 2.59.10.52 = * Replace the remaining hidden shared-cache and Varnish control enable flags with one internal, migration-safe Varnish connection state. * Activate Varnish runtime automatically after a dedicated connection save, a detected/configured custom endpoint, a legacy active integration, or an isolated capability probe. * Keep a fresh installation inactive when it contains only the untouched default endpoint, preventing default placeholders from creating shared-cache headers or endpoint registry profiles. * Make targeted invalidation, TTL fallback, affected-page refill, site warm-up participation, HTML-variant refill, stale refresh, refresh-ahead gating, performance measurement, diagnostics, Flush All, REST, and WP-CLI use the same derived connection state. * Preserve fail-closed capability planning: configured connections use only current verified operations and fall back automatically to bounded TTL expiry when exact invalidation is unavailable. * Migrate the previous enable values into `varnishConnectionConfigured`, remove the obsolete fields from canonical settings, REST schemas, CLI normalization, performance profiles, and dashboard state, and keep the legacy values readable only during migration. * Add a write-only connection intent to the dedicated Varnish Save action so the default local endpoint can be activated intentionally without restoring a user-facing enable switch. * Prevent inactive default endpoints from seeding the per-endpoint capability registry and keep isolated Test Varnish probes temporary. * Route WP-CLI Varnish state checks through the main UltraCache runtime helper and preserve the external/server cache card as the owner of Flush All Varnish inclusion. = 2.59.10.51 = * Make Automation & Scheduling the single source of truth for Varnish page lifetime, stale window, warm-up cadence, and refresh-ahead activation. * Derive the managed Varnish HTML TTL from Fresh TTL and the stale-refresh window from Fresh TTL, Max stale window, and the central Stale While Revalidate switch. * Derive the automatic-expiry fallback from the central Fresh TTL with a conservative internal ten-minute maximum instead of storing a second user-controlled Varnish TTL. * Remove the obsolete Varnish-specific TTL, stale, targeted-refill, site-warm, refresh-ahead, threshold, scan-limit, and pinned-URL settings from canonical defaults, validation, REST schemas, CLI normalization, and dashboard JavaScript state. * Automatically include verified Varnish in affected-page refill and every existing site warm-up pipeline instead of requiring separate Varnish switches. * Activate Varnish refresh-ahead only when the central Cron Warm Up and Stale While Revalidate automation are active and the required soft-purge behavior is verified. * Use Cron warm pages per minute as the bounded Varnish refresh-ahead work limit and keep the internal threshold policy automatic. * Remove the unused Varnish refresh-ahead dashboard module and preserve the Varnish card as connection, test, measurement, manual action, and simple status only. * Preserve the external/server cache layers card as the sole owner of whether Flush All Cache includes Varnish. * Leave both CWP Varnish templates unchanged. = 2.59.10.50 = * Restore the previously approved Varnish Cache card title and description instead of exposing the internal shared-cache/control architecture in the dashboard heading. * Remove the user-facing shared-cache delivery, managed invalidation, TTL-only, invalidation strategy, flush-scope, SWR, ESI, refill, Varnish warm-up, and refresh-ahead controls from the Varnish card. * Keep the Varnish card focused on connection mode, endpoints, secret/token, timeout, Detect, Test, bounded performance measurement, one capability-aware manual flush action, and a compact status summary. * Remove the separate entire-host flush button from the normal Varnish card; the remaining manual flush continues through the existing capability-driven runtime planner. * Automatically keep shared-cache delivery and Varnish control enabled when a valid endpoint configuration is saved, avoiding hidden enable switches that could leave a configured integration inactive. * Limit Varnish connection saves to connection-owned fields so the card no longer overwrites TTL, ESI, refill, warm-up, refresh, or scheduling values owned by other dashboard sections. * Leave the existing Also flush Varnish Cache option in the external/server cache layers card as the sole control for including Varnish in Flush All Cache. * Preserve all runtime planner, capability registry, canary, VCL contract, queue, measurement, CWP template, and stored-setting behavior outside this UI ownership cleanup. = 2.59.10.49 = * Add a bounded two-pass Varnish parent-cache performance snapshot for up to three trusted local URLs across the active original, WebP, and AVIF HTML variants, with a finite overall time budget and per-request timeout. * Keep the performance snapshot diagnostic-only: it may warm the sampled objects but does not purge Varnish, modify cache settings, or automatically tune ESI, cart-fragments, grace, keep, or refresh-ahead behavior. * Calculate second-pass HIT and cache-served rates only from visible cache-status evidence, and report signals-hidden instead of inferring a HIT rate when the host suppresses those signals. * Record passive ESI render telemetry with bounded 1-in-32 sampling, including estimated public/private request volume, average and maximum render duration, average output size, and a rolling 24-hour window. * Track WooCommerce classic mini-cart ESI traffic and render cost separately, while recording contained renderer errors without sampling so correctness failures remain visible. * Add compact production counters for capability-planner runtime outcomes and selected invalidation strategies without duplicating queue lifecycle state. * Show parent-cache samples, observed HTML variants, private and WooCommerce ESI cost, invalidation outcome health, sampling details, and measurement-based recommendations in the Varnish dashboard. * Invalidate stored performance measurements when shared-cache delivery or the active HTML variant policy changes, and remove the snapshot during plugin-data cleanup and uninstall. * Preserve the standalone CWP templates and the optional VCL contract byte-for-byte; this release changes plugin-side measurement and diagnostics only. = 2.59.10.48 = * Add an optional authenticated UltraCache CWP VCL v2 contract while preserving the standalone generic exact-PURGE path for sites without UltraCache or without the advanced contract enabled. * Keep the advanced contract disabled by default and require explicit template enablement plus a matching random HTTP control token before accepting structured operations. * Add versioned capability responses for exact PURGE, object-side exact and batch BAN, HTML-only BAN, entire-host BAN, ESI transport, and canonical HTML variants. * Route verified CWP contract endpoints through object metadata BAN expressions so exact, batch, HTML, and host invalidation are ban-lurker friendly. * Probe the contract independently on every configured HTTP endpoint and bind the adapter and capabilities to the existing isolated exact-invalidation canary proof. * Preserve generic HTTP PURGE/BAN and admin-socket adapters when the versioned contract is missing, disabled, unauthenticated, or unsupported. * Fall back immediately to the standalone generic exact-PURGE path when an authenticated contract exact-PURGE request fails, while never converting site-wide BAN operations into an unsafe PURGE / fallback. * Require a bounded 32-128 character ASCII letter/number/underscore/hyphen token before the plugin attempts the optional contract, and preserve non-default frontend ports in exact invalidation requests. * Confirm the VCL ban() boolean result before reporting a structured BAN operation as accepted. * Invalidate a stored contract profile when the endpoint later reports that the contract is disabled, missing, or no longer authenticated. * Do not advertise soft purge, SWR, or origin revalidation from the standalone CWP template because the per-domain template must not require an unverified purge VMOD import. * Show the number of endpoints using the authenticated VCL contract in the Varnish dashboard and clarify that the HTTP control key must match the optional template token. = 2.59.10.47 = * Upgrade both bundled Control Web Panel Varnish templates to standalone WordPress/WooCommerce v2 templates that remain fully functional without UltraCache. * Replace unanchored domain regex matching with exact CWP host comparison after removing an optional numeric Host port. * Add a local-direct, front-proxy-aware exact PURGE receiver that invalidates the requested cache key and all of its Vary variants without requiring an UltraCache-specific header or token. * Canonicalize cacheable HTML Accept headers into AVIF, WebP, or original buckets while respecting explicit q=0 exclusions, preventing equivalent browser Accept strings from fragmenting the Varnish object set. * Store normalized object host and URL metadata on cacheable responses for future ban-lurker-friendly obj.http invalidation, and remove those internal headers before client delivery. * Keep grace and keep as independent standalone policies, using ten minutes of grace for refresh/origin protection and a smaller five-minute keep window for conditional revalidation. * Preserve the conservative WooCommerce PASS policy in the global-safe template and the existing explicit request/response approval handshake in the ESI template. = 2.59.10.46 = * Add a capability-driven Varnish runtime planner that selects targeted invalidation, site flush, queue processing, refill, and site-warm behavior only from current per-endpoint proofs. * Normalize every Varnish runtime result as complete, partial, degraded, unsupported, or failed, and expose the selected strategy, fallback, execution state, and sanitized plan to REST, diagnostics, dashboard, action queue, and WP-CLI callers. * Use verified exact PURGE/BAN for targeted operations; when soft purge is configured but not behavior-verified, fall back to verified hard invalidation and report the result as degraded instead of claiming soft-purge success. * Replace unsupported site-wide assumptions with a bounded known-local-URL fallback when exact invalidation is verified, while explicitly retaining unknown or uncrawled objects for TTL expiry. * Queue large known-URL fallback sets persistently and bound the synchronous fallback to 20 URLs when the queue is unavailable, leaving the remainder to the configured TTL-only window rather than issuing thousands of requests in one action. * Prioritize persistent Varnish invalidation rows ahead of site warming so a delayed fallback operation cannot purge objects that the same warm pipeline has already refreshed. * Re-evaluate capability proofs when queued invalidations run; expired or incomplete proof moves those rows to a degraded TTL-expiry result without sending unverified PURGE/BAN requests or scheduling a misleading refill. * Gate Varnish site warm/refill work on the current targeted runtime plan, while allowing the isolated capability canary to exercise a configured transport before proof exists. * Keep direct HTML-only and entire-host transport calls restricted to bounded topology tests; production site operations now pass through the runtime planner. = 2.59.10.45 = * Run a separate mutable generation canary through every configured HTTP Varnish endpoint instead of assigning one aggregate result to the full topology. * Route canary warm-up, cache-retention proof, exact PURGE/BAN, post-invalidation verification, and refill verification through the same endpoint with the original frontend Host header. * Store exact-invalidation proof only on the endpoint that independently changed its WordPress-served canary from generation 1 to generation 2; clear only the failing endpoint profile when its latest proof fails. * Report working, partial-topology, and endpoint-proofs-failed results with per-endpoint reachability, transport acceptance, shared-cache evidence, and bounded failure details. * Keep runtime invalidation disabled unless every configured endpoint has a current exact-invalidation proof, while preserving static-route-only evidence without treating it as WordPress page coverage. * Synchronize the complete per-endpoint result set into the capability registry before removing verbose probe steps from the persisted diagnostic payload. * Execute Varnish behavior tests in the main UltraCache class scope so private integration helpers remain callable, while retaining the previous test-runner class as a compatibility facade. * Keep multi-endpoint ESI inactive until a separate per-endpoint ESI behavior probe verifies every active node. = 2.59.10.44 = * Add a non-autoloaded, bounded Varnish capability registry with one configuration-bound profile per configured endpoint. * Track endpoint adapter, reachability evidence, exact PURGE/BAN, batch BAN, HTML-only and host flush, soft purge, origin revalidation, SWR, public/private ESI, HTML variants, proof timestamps, source, status, and bounded failure details. * Evaluate managed capabilities as the intersection of every active endpoint so mixed or partially verified topologies cannot be reported as fully managed. * Start each newly registered HTTP endpoint without inherited capability assumptions; each endpoint receives capability state only from its own current proof or an explicit native transport contract. * Keep native Varnish admin BAN contracts per endpoint while maintaining separate reachability evidence and non-expiring native capability contracts. * Synchronize Test Varnish results into endpoint profiles and return a truthful mixed-topology result when one aggregate canary cannot independently prove multiple HTTP endpoints. * Gate exact invalidation, site-wide scopes, soft purge, SWR, refresh ahead, and ESI through current per-endpoint capability intersection. * Expose the endpoint capability matrix through dashboard diagnostics and remove its option during plugin-data cleanup and uninstall. = 2.59.10.43 = * Separate standard shared-cache HTML delivery from managed Varnish control, allowing portable s-maxage delivery even when no PURGE/BAN endpoint is configured or verified. * Add a dedicated shared-cache switch and a bounded TTL-expiry-only value for hosts where invalidation is unavailable, incomplete, or no longer behavior-verified. * Preserve existing Varnish-enabled installations by treating the new shared-cache delivery switch as enabled until the new setting is explicitly saved. * Use the normal page-cache TTL only when both exact URL and site-wide invalidation coverage are available; exact-only HTTP control continues to accelerate targeted invalidation while shared delivery remains on the shorter TTL. * Keep ESI, stale-while-revalidate, refill, and refresh-ahead dependent on shared delivery plus the required verified Varnish capabilities. * Carry managed and TTL-only lifetimes separately into the PHP engine and generated advanced-cache.php, and automatically downgrade the drop-in when a time-bounded HTTP capability proof expires. * Refresh generated page-cache runtime artifacts after Varnish canary capability results change, while keeping Apache Static HTML Delivery on the conservative TTL for time-bounded HTTP proofs. * Expose shared-cache delivery mode, effective TTL, control verification, and proof status in dashboard diagnostics and the reorganized Shared Cache & Varnish Control card. = 2.59.10.42 = * Add isolated Varnish generation canaries below uploads/ultracache/varnishtest, with WordPress path, query fallback, and direct-upload route probes while bypassing UltraCache page cache. * Verify managed HTTP exact-URL invalidation by retaining generation 1, mutating the same canary to generation 2, invalidating the exact URL, and requiring the new generation to appear and remain stable after refill. * Treat direct-upload-only proof as static-cache evidence rather than authorization for managed WordPress page invalidation, and expire HTTP behavior proofs after seven days. * Keep Varnish discovery results as unsaved candidates until Test Varnish proves behavior, and distinguish transport acceptance from public invalidation verification. * Gate synchronous and queued HTTP runtime invalidation on the current canary proof; unverified transports fall back to cache TTL expiry instead of reporting successful purge behavior. * Stop treating generic HTTP PURGE or BAN as portable HTML-only or entire-host flush contracts; keep site-wide actions unavailable until native admin BAN or an independent topology proof supports the requested scope. * Route both existing Varnish test REST actions through the same exact-URL canary test and leave the bundled CWP Varnish templates unchanged. = 2.59.10.41 = * Moved Image conversion test and Check test below Image compression level in the adjacent media-settings column. * Aligned the Media Library Replacement heading and overview with the Convert new uploads settings-row design. * Preserved all existing conversion-test and Media Library Replacement actions, guards, jobs, and test behavior. = 2.59.10.40 = * Add a Media Library Replacement workflow title and concise overview above the existing four primary actions. * Rename the primary workflow buttons to Prepare Replacement, Apply Replacement, Verify Replacement, and Delete Original Files, including clearer running, resume, retry, and completion labels. * Add a short explanation below each primary action while preserving the existing workflow order, handlers, guards, resumable jobs, status logic, and advanced recovery controls. = 2.59.10.39 = * Fix the Help FAQ CWP Varnish template downloads by exposing dashboard runtime data before the reusable UI module initializes, so both bundled `.tpl` buttons are rendered and downloadable. * Remove the redundant post-install informational box and add Delay non-critical/local JS as step 2 in the PageSpeed guidance, with the existing selective-options warning moved to step 3. * Update the Aggressive profile Delayed JS auto-start controls to use Mouse move and Scroll event triggers with a 2 second fallback timer. = 2.59.10.38 = * Simplify Detect Varnish Configuration to one public homepage probe: a portable Varnish response header is sufficient to confirm that the site is behind Varnish. * Test the bounded configured, loopback, local-address, server-hostname, and reverse-DNS HTTP candidates directly with PURGE first and BAN second, then stop at the first accepted Varnish response and save its endpoint and method automatically. * Remove temporary discovery files, signed probe URLs, warm-up loops, HIT-to-MISS-to-HIT verification, admin-socket probing, verbose attempt payloads, and related discovery-only cleanup. The existing Test Varnish behavior test remains unchanged. * Keep the unsaved-settings reminder only for manual field changes. = 2.59.10.37 = * Make behavior-verified Varnish discovery apply and save the detected HTTP endpoint, method, timeout, invalidation strategy, and flush scope immediately, so the working configuration does not depend on a second manual save action. * Return only the bounded actionable discovery result to REST instead of provider response bodies and verbose probe attempts, preventing successful detection from being lost before the dashboard can update. * Update the Varnish form and saved-settings reference from the verified result so Test Varnish is available immediately. Manual field changes continue to show the existing Save Varnish Settings reminder. = 2.59.10.36 = * Keep every Varnish discovery result JSON-serializable by stripping invalid UTF-8 from provider responses, error messages, array keys, and nested result values before REST output. * Truncate invalidation-response summaries by UTF-8 characters instead of raw bytes, preventing multilingual WordPress HTML from being cut inside a multibyte character and causing HTTP 200 responses with an empty body. * Convert unexpected WP_Error, object, resource, and non-finite numeric values in Varnish diagnostic results into bounded JSON-safe representations instead of allowing REST serialization to fail silently. = 2.59.10.35 = * Add Detect Varnish Configuration to test a bounded set of configured, loopback, local-address, server-hostname, and reverse-DNS candidates on common Varnish ports without scanning arbitrary hosts. * Verify HTTP PURGE and BAN candidates against isolated short-lived cacheable probe objects, requiring observable HIT to MISS/STALE to HIT behavior before filling the Varnish connection fields. Detect Varnish admin sockets and authenticated HTTP listeners when their secret or control key must be supplied separately. * Fill detected settings without saving them, show an explicit unsaved-settings reminder, and block Detect, Test Varnish, and flush actions until Save Varnish Settings commits the current fields. * Accept successful HTML synthetic invalidation responses only when a 2xx response includes portable Varnish evidence and an invalidation confirmation, including managed-host responses such as HTTP 200 Purged with X-Varnish. = 2.59.10.34 = * Make a saved per-URL Manual LCP selector immediately replace competing automatic winners with authoritative locked mobile, tablet, and desktop mappings; diagnostics now show the manual source and selector immediately instead of the previous automatic candidate, and repair already-saved selector scopes when their URL details are opened. = 2.59.10.33 = * Prevent the Aggressive performance profile from enabling Delay non-critical/local JS. = 2.59.10.32 = * Autosave Enable ESI fragment framework, Refill affected pages after targeted invalidation, Warm Varnish with site warm-up, and Refresh hot pages before expiry immediately when their switches change. * Save each switch through the existing partial settings endpoint as an isolated boolean patch, so unsaved Varnish endpoints, secrets, timeout, dropdowns, thresholds, and pinned URLs are never included in the autosave request. * Keep Save Varnish Settings for the remaining connection and advanced fields, and preserve the existing optimistic dashboard state, serialized save queue, server canonical response, success/error toast, and infrastructure-lock behavior. * No cache runtime, VCL, ESI capability, queue, database, or server-template contract changes. = 2.59.10.31 = * Build the private ESI cookie carrier from the explicit built-in allowlist instead of copying the complete browser Cookie header. The suggested CWP templates and Help VCL transport only `esi_session`, `woocommerce_items_in_cart`, `woocommerce_cart_hash`, and one `wp_woocommerce_session_*` cookie. * Restore private cookies only for signed UltraCache fragment endpoints carrying `esi_scope=private`; unrelated same-origin ESI includes cannot opt into the private/session carrier by adding the scope parameter alone. * Mark private ESI subrequests as `X-Cache: PASS` before `return (pass)` so frontend diagnostics reflect their actual delivery mode. * Apply the same transport hardening to the recommended CWP template, conservative global-safe template, and copyable Help VCL. Keep the existing CWP `%domain%` host-placeholder matching unchanged because its expansion is controlled by the active CWP template contract. * Preserve the 20-second frontend ESI probe timeout, request opt-in handshake, canonical manual-warm redirect handling, and ESI capability contract; this VCL-only hardening requires template replacement/rebuild but no new plugin-side capability contract. = 2.59.10.30 = * Make the Public ESI, Private ESI, and Woo mini-cart ESI dashboard rows reflect the current stored Test Varnish verification proof instead of the separate runtime `effective` gate. A fully verified proof can no longer appear as `Fallback only` or `Test required`, and a successful ESI message is no longer rendered as a warning. * Follow at most one HTTP 301/302/303/307/308 redirect during staged manual Varnish refill only when `Location` resolves to a verified local frontend URL. The canonical target is invalidated before the first refill bucket, then reused by the remaining Varnish and LiteSpeed stages. * Reject external, malformed, and redirect-chain destinations without following them, and expose the HTTP code plus redirect destination in the returned warm-up error instead of the generic `Varnish ORIG bucket refill failed` message. * Preserve the independent 20-second frontend ESI probe timeout, the request-opt-in handshake, and the existing ESI capability contract; a new Test Varnish run is not required solely for this update. = 2.59.10.29 = * Add the request-side `ultracache_esi_optin=1` browser handshake used by the recommended CWP VCL. The host-only session cookie is created only on pages that actually render the verified classic WooCommerce mini-cart ESI adapter; it is stripped by Varnish before origin/cache lookup. * Restrict `X-UltraCache-ESI-Shared-Parent: 1` approval to cached parents whose trusted ESI metadata contains the exact `woocommerce-mini-cart` private fragment. Generic private fragments can no longer opt WooCommerce visitors into a shared parent. * Upgrade atomic `.esi` sidecars to version 4 with a bounded `woocommerceMiniCart` flag, preserving older sidecars as valid ESI parents but never as Woo shared-parent approvals. * Update the private/Woo Test Varnish probe to send the request opt-in marker, keep the independent 20-second frontend ESI timeout, bundle the matching CWP template, and update Help → FAQ plus the copyable VCL snippet. * Protect the new marker helper from UltraCache defer/delay transforms. No visitor identifier, cart value, session ID, or persistent expiry is stored in the marker cookie. = 2.59.10.28 = * Add the explicit `X-UltraCache-ESI-Shared-Parent: 1` response handshake used by the unified Varnish template. Anonymous cacheable ESI parents containing private fragments may be approved for later WooCommerce-cookie HIT reuse; candidate cache misses retain their real cookies and remain uncacheable. * Approve the signed private/session capability-probe parent so Test Varnish can verify shared-parent reuse, isolated no-store private fragments, and WooCommerce cookie transport against the unified template. * Decouple frontend ESI composition requests from the Varnish admin endpoint timeout. Public/private/Woo probes now use a bounded independent 20-second timeout while admin socket operations retain their configured limit. * Bundle both the recommended Control Web Panel handshake template and a conservative global-safe/PASS alternative, and update Help → FAQ plus the generic copyable VCL suggestion to describe the approval contract and both downloads. * Bump the ESI capability contract so existing proofs require one new Test Varnish run after installing the matching plugin/template pair. = 2.59.10.27 = * Replace the bundled Control Web Panel Varnish template with the global-safe variant. Standard WooCommerce cart and session cookies remain on top-level requests so mixed CWP servers keep normal PASS behavior and shops without UltraCache cannot lose cart state. * Keep public ESI and private/session transport plumbing in the shared template while making the classic WooCommerce mini-cart shared-parent optimization an explicit per-domain opt-in instead of a global behavior. * Make both the bundled CWP template and the generic copyable Help VCL snippet global-safe, and explain the WooCommerce PASS guarantee plus the separate per-domain mini-cart ESI requirement. * No cache engine, ESI capability, queue, database, or automatic server-configuration runtime changes. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/admin/js/ui.js`, and `resources/varnish/control-web-panel/ultracache-wordpress-woocommerce-esi.tpl`. = 2.59.10.26 = * Expand Help → FAQ with the actual public ESI, private/session ESI, and WooCommerce classic mini-cart transport requirements, plus the meaning of Verified, VCL update required, and Fallback only after Test Varnish. * Add “I need a ready solution for my Control Web Panel (CWP) server.” with a clearly labelled Suggested ready-to-use configuration and direct download button. * Bundle `resources/varnish/control-web-panel/ultracache-wordpress-woocommerce-esi.tpl`, preserving the CWP `%domain%`, `%backend_domain%`, `%proxy_ip%`, and `%proxy_port%` placeholders and including the tested WordPress/WooCommerce/public/private ESI rules. * Expose the bundled same-origin template URL through the existing dashboard bootstrap configuration. No Varnish file is installed or changed automatically, and no cache, ESI capability, or queue runtime contract changes. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/admin/class-admin-trait.php`, `includes/admin/js/ui.js`, and new `resources/varnish/control-web-panel/ultracache-wordpress-woocommerce-esi.tpl`. = 2.59.10.25 = * Fix the WooCommerce private ESI transport proof so its diagnostic endpoint reads the original bounded backend `Cookie` header. WooCommerce normalization can no longer hide `woocommerce_items_in_cart` or `woocommerce_cart_hash` after Varnish has transported them correctly. * Treat `time_budget` and `memory_budget` warm-up pauses as cooperative queue yields instead of failed attempts. The owned row returns to `pending`, its claim attempt is restored, and the existing cron worker continues it on the next tick without reaching the terminal retry limit. * Keep normal HTTP, origin, cache-write, and integration failures on the existing retry/error path. No queue migration, VCL change, ESI contract change, or new background subsystem is introduced. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/esi/class-esi-endpoint-trait.php`, `includes/warmup/class-warm-runner-trait.php`, and `includes/warmup/class-cron-warm-orchestrator-trait.php`. = 2.59.10.24 = * Correct the completed-test status classification for private ESI and the WooCommerce classic mini-cart adapter. When public ESI is verified but the private cookie transport is absent, both rows now report `VCL update required` instead of `Fallback only` or `Test required`. * Stop presenting the lifetime `refillFailures` metric as an active operational failure. The Varnish refill row now reflects the current test or active shared warm queue state, while historical counters remain available only in metrics diagnostics. * Add a bounded sample of current terminal Varnish queue rows to diagnostics. Each detail includes the failed invalidation/refill type, URL, stored error message, attempt count, failure time, and stopped-retry state. * Replace the generic `require attention` queue warning with actionable output that identifies what failed and tells the administrator which invalidation/test or warm-up action to run again after fixing the reported transport/origin error. * Keep the Varnish/ESI capability contracts and server VCL unchanged; this plugin-only bugfix does not require a new Test Varnish run when the existing proof is valid. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/integrations/varnish/class-varnish-queue-trait.php`, and `includes/admin/js/varnish.js`. = 2.59.10.23 = * Fix bounded Varnish test-result storage so capability fingerprints and contract versions are attached after large diagnostic steps are compacted. Successful public/private ESI proofs therefore remain authoritative instead of immediately appearing as `configuration-changed` or `Run test again`. * Move the generic public/private-session ESI VCL snippet out of the Varnish operational settings and into Help → FAQ under “My Varnish server has only a basic setup. How can I enable ESI and WooCommerce mini-cart support?”. * Label the snippet explicitly as a suggested generic configuration that is not installed automatically and must be merged into the existing VCL, reviewed, compiled, reloaded, and followed by Test Varnish. * Keep the ESI capability contract unchanged from 2.59.10.22; this bugfix does not invalidate an otherwise complete stored proof. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/integrations/varnish/class-varnish-test-action-trait.php`, `includes/integrations/varnish/class-varnish-esi-capability-trait.php`, `includes/admin/js/varnish.js`, and `includes/admin/js/ui.js`. = 2.59.10.22 = * Harden composite ESI parent delivery by suppressing origin ETag/Last-Modified validators and conditional `304 Not Modified` responses for marked ESI parents in both the WordPress early-hit path and generated `advanced-cache.php`. Non-ESI cached HTML retains the existing GET/HEAD validator behavior. * Add bodyless fragment `HEAD` handling that validates signed context and private transport without invoking render callbacks. Fragment responses remove validators and content length, while GET renderer failures and soft time-budget overruns are contained through the registered fallback and returned as no-store responses. * Add `max_render_ms` per fragment, a 32-include/64 KiB generated-directive parent budget with bounded filters, and fragment-output neutralization for nested or untrusted ESI directives. Excess parent placeholders remain inline fallback HTML rather than creating additional subrequests. * Bind deterministic fragment tokens and context hashes to the active WordPress locale, switch the fragment endpoint to that locale during rendering, and restore the original locale afterward so native translated output cannot share a fragment URL across locales. * Bump the Varnish ESI capability contract so existing proofs require a new Test Varnish run after the hardening upgrade. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `templates/advanced-cache.php.tpl`, `includes/class-ultra-cache-engine.php`, `includes/esi/functions.php`, `includes/esi/class-esi-registry.php`, `includes/esi/class-esi-rendering-trait.php`, `includes/esi/class-esi-endpoint-trait.php`, `includes/engine/class-engine-storage-trait.php`, `includes/engine/class-engine-response-headers-trait.php`, and `includes/integrations/varnish/class-varnish-capability-fingerprint-trait.php`. = 2.59.10.21 = * Add an explicit WooCommerce classic mini-cart private ESI adapter with the template helpers `ultracache_get_woocommerce_esi_mini_cart_markup()` and `ultracache_render_woocommerce_esi_mini_cart()`, plus the `[ultracache_esi_mini_cart]` shortcode. The shared parent contains only a static generic cart link fallback; live cart HTML is rendered exclusively by the private no-store fragment. * Register a strict WooCommerce cookie scope for `woocommerce_items_in_cart`, `woocommerce_cart_hash`, and the `wp_woocommerce_session_` prefix. Extend Test Varnish with WooCommerce-specific cookie transport markers and require that proof before the built-in adapter may emit a private ESI include. * Keep WooCommerce cart/checkout/account whole-page bypass behavior unchanged and integrate the classic adapter with the standard `div.widget_shopping_cart_content` replacement selector. When the adapter is rendered, UltraCache preserves the native `wc-cart-fragments` runtime and disables its optional delay/suppress controls for that request so add/remove-cart events refresh the mini-cart. * Keep the WooCommerce Mini-Cart block separate from the classic adapter; the block continues using its Store API/Interactivity runtime and is not rewritten automatically. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/class-ultra-cache-engine.php`, `includes/engine/class-engine-frontend-assets-trait.php`, `includes/esi/class-esi-endpoint-trait.php`, `includes/integrations/varnish/class-varnish-capability-fingerprint-trait.php`, `includes/integrations/varnish/class-varnish-esi-capability-trait.php`, `includes/admin/js/varnish.js`, and new `includes/integrations/woocommerce/class-woocommerce-esi-trait.php`, `includes/integrations/woocommerce/functions.php`, and `includes/integrations/woocommerce/index.php`. = 2.59.10.20 = * Add private ESI fragment scope with exact cookie-name/prefix allowlists, zero shared TTL, bounded cookie-header filtering, mandatory static anonymous parent fallback rendering, current-user revalidation inside the fragment request, and explicit rejection from the public-fragment purge API. * Add generic `req_top` private-session VCL transport rules with top-request spoofed-header stripping, public-fragment cookie removal, private-subrequest pass/no-store enforcement, and a per-definition transport-policy gate so a verified probe cannot enable cookies that were not also declared in VCL. * Extend Test Varnish with repeated same-session and cross-session private transport verification against one shared parent. The proof requires isolated session output, identical parent render identity, a new private-fragment render identity on every delivery, no shared fragment storage, and successful `onerror="continue"` error containment. * Upgrade ESI parent metadata to version 3 with separate public/private reference counts and expose private-scope capability status in the Varnish card plus public/private parent counts in the WordPress and `advanced-cache.php` response paths. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `templates/advanced-cache.php.tpl`, `includes/esi/functions.php`, `includes/esi/class-esi-registry.php`, `includes/esi/class-esi-rendering-trait.php`, `includes/esi/class-esi-endpoint-trait.php`, `includes/engine/class-engine-storage-trait.php`, `includes/engine/class-engine-response-headers-trait.php`, `includes/integrations/varnish/class-varnish-capability-fingerprint-trait.php`, `includes/integrations/varnish/class-varnish-esi-capability-trait.php`, and `includes/admin/js/varnish.js`. = 2.59.10.19 = * Add exact public ESI fragment invalidation through `ultracache_purge_esi_fragment()`. The API derives the deterministic signed fragment URL for one normalized context, invalidates only that Varnish object, leaves parent pages intact, returns a bounded operation result, and records dedicated production invalidation counters without duplicating the existing generic Varnish operation totals. * Enforce definition-level total context and individual value byte limits in addition to the existing context-key allowlist, scalar-only values, token signature, output limit, and nesting guard. Add callback-free definition and stable context-hash inspection APIs for integrations. * Upgrade ESI parent sidecars to version 2 with bounded unique-fragment and minimum/maximum fragment-TTL metadata while retaining compatibility with version 1 sidecars. Publish the compact lifecycle metadata from normal WordPress and `advanced-cache.php` delivery paths. * Extend Varnish refill and shared warm-pipeline results with ESI parent-variant, fragment-reference, unique-reference, and TTL counters. Add compact fragment endpoint context, byte-size, and render-duration headers plus a render metrics action for external analytics. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `templates/advanced-cache.php.tpl`, `includes/esi/functions.php`, `includes/esi/class-esi-registry.php`, `includes/esi/class-esi-rendering-trait.php`, `includes/esi/class-esi-endpoint-trait.php`, new `includes/esi/class-esi-lifecycle-trait.php`, `includes/engine/class-engine-storage-trait.php`, `includes/engine/class-engine-response-headers-trait.php`, `includes/integrations/varnish/class-varnish-refill-trait.php`, `includes/integrations/varnish/class-varnish-metrics-trait.php`, and `includes/warmup/class-warm-page-pipeline-trait.php`. = 2.59.10.18 = * Add a short-lived signed parent/fragment probe to Test Varnish and verify real ESI composition across identity, gzip, and Brotli-client requests. The test confirms fragment output, independent fragment-object reuse across repeated parent deliveries, inline-fallback removal, blocked raw ESI markup, and a composed cache HIT when cache-status signals are visible. * Persist an independent ESI capability proof fingerprinted to the current Varnish transport and site contract, expose it through diagnostics and the Varnish card, and keep normal registered fragments on inline fallback HTML until both the administrator switch and the verified proof are active. * Add a copyable generic Varnish ESI configuration snippet, including backend compression normalization, and add lifecycle/uninstall cleanup for the stored capability result. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `uninstall.php`, `includes/esi/functions.php`, `includes/esi/class-esi-endpoint-trait.php`, `includes/integrations/class-varnish-trait.php`, `includes/integrations/varnish/class-varnish-capability-fingerprint-trait.php`, `includes/integrations/varnish/class-varnish-test-action-trait.php`, `includes/integrations/varnish/class-varnish-behavior-test-trait.php`, new `includes/integrations/varnish/class-varnish-esi-capability-trait.php`, `includes/diagnostics/class-diagnostics-rest-trait.php`, `includes/lifecycle/class-plugin-data-cleanup-trait.php`, and `includes/admin/js/varnish.js`. = 2.59.10.17 = * Add an atomic `.esi` sidecar for cached parent HTML containing trusted ESI includes, with bounded versioned fragment metadata shared by normal STORE writes, explicit warm writes, the WordPress early-hit path, and `advanced-cache.php`. * Emit `Surrogate-Control: content="ESI/1.0"` plus ESI parent diagnostics only for marked parent responses, while stale/non-cacheable ESI parents retain a no-store surrogate contract and inline fallback behavior. * Keep ESI parents on identity/gzip representations, remove and skip Brotli variants, remove and skip Apache Static HTML aliases, and restore or remove sidecars correctly across failed writes and ESI-to-non-ESI transitions. * Remove `.esi` sidecars during targeted purge, cache-variant cleanup, and stale generated-CSS invalidation. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/class-ultra-cache-engine.php`, `includes/esi/class-esi-rendering-trait.php`, `includes/engine/class-engine-response-headers-trait.php`, `includes/engine/class-engine-storage-trait.php`, and `templates/advanced-cache.php.tpl`. = 2.59.10.16 = * Add the opt-in public ESI fragment foundation with a registry-based developer API, public-only scope enforcement, bounded context keys and output size, deterministic HMAC-signed context tokens, and a same-origin read-only fragment endpoint. * Render inline server-side fallback HTML when ESI is disabled or not processed, convert token-matched UltraCache placeholders at the end of the canonical STORE/warm HTML pipeline into `` plus `` markup, and neutralize unrelated raw ESI directives before trusted directives are inserted. * Add the disabled-by-default ESI framework switch to the Varnish card and route it through canonical settings defaults, validation, REST schema, import/export, profile preservation, infrastructure permissions, and runtime mapping. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/class-ultra-cache-engine.php`, `includes/bootstrap/class-bootstrap-trait.php`, `includes/settings/class-settings-registration-trait.php`, `includes/settings/class-settings-rendering-trait.php`, `includes/settings/class-settings-persistence-trait.php`, `includes/settings/class-settings-validation-trait.php`, `includes/rest/class-rest-schemas-trait.php`, `includes/rest/class-rest-cache-trait.php`, `includes/admin/js/settings.js`, `includes/admin/js/lifecycle.js`, `includes/admin/js/varnish.js`, `includes/admin/js/dashboard-application.js`, and new `includes/esi/` files. = 2.59.10.15 = * Convert the Varnish and LiteSpeed integration cards into gated accordions with their main enable switches in the accordion headers. Enabling opens the integration automatically, disabling closes it, and disabled integrations cannot expose their configuration, actions, diagnostics, counters, or history. * Gray and lock Apache Static HTML Delivery while Native LiteSpeed HTML Cache is active, and lock the LiteSpeed main switch while Apache Static HTML Delivery is active. Both disabled states expose explicit hover warnings while the existing backend mutual-exclusion contract remains enforced. = 2.59.10.14 = * Make Native LiteSpeed HTML Cache and Apache Static HTML Delivery mutually exclusive across dashboard toggles, REST saves, imports, profiles, WP-CLI, persistence, and runtime settings normalization. Enabling either mode now disables the other in the same atomic settings save. * Resolve conflicting legacy/imported payloads deterministically in favor of Native LiteSpeed HTML Cache, preventing both server-level HTML delivery paths from remaining active together. = 2.59.10.13 = * Publish the native LiteSpeed TTL, site tag, exact URL tag, and `orig`/`webp`/`avif` vary contract from the early `advanced-cache.php` page-cache hit path. * Keep stale UltraCache hits, query-string hits, and conditional `304 Not Modified` responses out of LSCache with `X-LiteSpeed-Cache-Control: no-cache`. = 2.59.10.12 = * Fix LiteSpeed managed-rule diagnostics so the guarded `.htaccess` read uses the authorized `litespeed_cache` filesystem context. Existing `# BEGIN/END UltraCache LiteSpeed Cache` rules are now detected correctly instead of being reported as `Not active`. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, and `includes/integrations/litespeed/class-litespeed-diagnostics-trait.php`. = 2.59.10.11 = * Consolidate the complete LiteSpeed integration into one full-width LiteSpeed card, matching the Varnish dashboard architecture. Native HTML cache enablement, targeted refill, site-warm inclusion, stale regeneration, refresh ahead, threshold/page limits, pinned URLs, Flush All inclusion, behavior testing, direct purge, and redetection now live together. * Keep the LiteSpeed card visible whenever LiteSpeed is detected or any LiteSpeed setting is configured, so the behavior-test prerequisite can be enabled from the same card instead of from the general Cache Engine section. * Move LiteSpeed origin evidence, managed-rule status, purge transport, active HTML buckets, observed `X-LiteSpeed-Cache`/`X-QC-Cache` headers, behavior results, production counters, refresh-ahead status, and recent operation history into the same card. * Remove duplicate LiteSpeed summaries from Diagnostics, Advanced Diagnostics, Reverse Proxy Details, and External Cache Flush settings. The main LiteSpeed card is now the single dashboard surface for LiteSpeed configuration and telemetry. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/admin/js/cache.js`, `includes/admin/js/dashboard-application.js`, and `includes/admin/js/dashboard-diagnostics-ui.js`. = 2.59.10.10 = * Fix the Advanced Diagnostics dashboard crash introduced in 2.59.10.09 by defining the LiteSpeed diagnostics payload inside the `AdvancedDiagnosticsCard` component scope before rendering native-cache, stale-purge, refresh-ahead, behavior-test, and refill telemetry. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, and `includes/admin/js/dashboard-diagnostics-ui.js`. = 2.59.10.09 = * Add opt-in LiteSpeed stale exact-URL tag invalidation using the signed blocking control response. Affected pages may remain available as stale while UltraCache regenerates them, while the final pre-refill purge and the behavior test remain hard exact purges for deterministic replacement. * Add a bounded LiteSpeed refresh-ahead candidate registry sourced from pinned URLs, home/posts/shop pages, selected menus, cache analytics, and sitemaps. Candidate URLs are normalized to the current site, deduplicated, prioritized, retained within fixed limits, and scheduled independently from Varnish candidates. * Determine refresh eligibility from the actual UltraCache `orig`, `webp`, and `avif` HTML files and their `.fresh` markers against the existing Fresh TTL and administrator-selected threshold. Missing required buckets are eligible immediately; no uncertain LiteSpeed `Age` header is used. * Route due LiteSpeed candidates through the existing persistent page-warm queue, per-page lock, lease heartbeat, retry classification, and warm pipeline. Each claimed page is rechecked, stale-purged, rebuilt, hard-purged, and refilled without adding a separate background worker; LiteSpeed discovery runs before Varnish discovery so an always-due Varnish scan cannot starve the independent LiteSpeed registry. * Add stale-purge and refresh-ahead controls, bounded scanner status, source/count diagnostics, independent stale-purge counters, recent operation context, lifecycle cleanup, Help text, documentation, REST/settings mappings, and translations. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `uninstall.php`, `includes/integrations/litespeed/class-litespeed-control-trait.php`, `includes/integrations/litespeed/class-litespeed-metrics-trait.php`, `includes/integrations/litespeed/class-litespeed-diagnostics-trait.php`, `includes/integrations/litespeed/class-litespeed-refill-trait.php`, `includes/integrations/litespeed/class-litespeed-refresh-candidates-trait.php`, `includes/integrations/litespeed/class-litespeed-refresh-ahead-trait.php`, `includes/runtime/class-runtime-cache-services-trait.php`, `includes/maintenance/class-scheduled-maintenance-trait.php`, `includes/warmup/class-cron-warm-orchestrator-trait.php`, `includes/settings/class-settings-registration-trait.php`, `includes/settings/class-settings-rendering-trait.php`, `includes/settings/class-settings-validation-trait.php`, `includes/settings/class-settings-persistence-trait.php`, `includes/rest/class-rest-cache-trait.php`, `includes/rest/class-rest-routes-trait.php`, `includes/rest/class-rest-schemas-trait.php`, `includes/lifecycle/class-plugin-data-cleanup-trait.php`, `includes/admin/js/cache.js`, `includes/admin/js/dashboard-application.js`, `includes/admin/js/dashboard-diagnostics-ui.js`, `includes/admin/js/help.js`, `includes/admin/js/lifecycle.js`, and `includes/admin/js/settings.js`. = 2.59.10.08 = * Add a canonical native LiteSpeed behavior test that runs two public GET requests for every active `orig`, `webp`, and `avif` HTML bucket, one shared blocking exact-URL purge, and two additional public GET requests per bucket. PASS requires an observable post-purge MISS followed by HIT; hidden LiteSpeed/QUIC.cloud cache signals return INCONCLUSIVE rather than a false success. * Add bounded production LiteSpeed telemetry for site purge, exact-URL purge, invalidated URL, and refill outcomes, including observed HIT, MISS, BYPASS, and hidden-signal counts. Diagnostic behavior-test traffic is explicitly excluded from production counters. * Store and display the latest 30 sanitized LiteSpeed operations with context, bucket, HTTP/cache status, duration, counts, and local path only. Query strings, response bodies, and remote URLs are not retained. * Extend the LiteSpeed dashboard card, Advanced Diagnostics payload, REST/API controller, external-cache detection schema, Help text, documentation, deactivation/uninstall cleanup, and translations with behavior-test results, per-bucket findings, production counters, and recent operation history. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `uninstall.php`, `includes/integrations/litespeed/class-litespeed-metrics-trait.php`, `includes/integrations/litespeed/class-litespeed-diagnostics-trait.php`, `includes/integrations/litespeed/class-litespeed-control-trait.php`, `includes/integrations/litespeed/class-litespeed-refill-trait.php`, `includes/runtime/class-runtime-cache-services-trait.php`, `includes/diagnostics/class-diagnostics-rest-trait.php`, `includes/rest/class-rest-litespeed-trait.php`, `includes/rest/class-rest-routes-trait.php`, `includes/lifecycle/class-plugin-data-cleanup-trait.php`, `includes/admin/js/api.js`, `includes/admin/js/cache.js`, `includes/admin/js/dashboard-application.js`, `includes/admin/js/dashboard-diagnostics-ui.js`, and `includes/admin/js/help.js`. = 2.59.10.07 = * Add independent LiteSpeed controls for targeted affected-page refill and inclusion in homepage, menu, full-site, cron, CLI, and warm-after-flush page pipelines. * Extend the existing shared per-page warm contract to complete UltraCache HTML and configured CSS work first, dispatch one blocking exact LiteSpeed purge, and then issue one anonymous public GET for every active `orig`, `webp`, and `avif` HTML bucket. * Route successful targeted LiteSpeed invalidations into the existing persistent page-warm queue, retaining queue coalescing, manual-job priority, per-URL locking, lease heartbeats, retry classification, and pause/resume checkpoints without adding a separate worker. * Extend the staged dashboard crawler, REST stage contract, cron status, completion counters, Help text, and settings import/profile preservation for LiteSpeed warm results. Explicit LiteSpeed bypass responses are not counted as successful refills. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/integrations/litespeed/class-litespeed-control-trait.php`, `includes/integrations/litespeed/class-litespeed-refill-trait.php`, `includes/warmup/class-cron-warm-orchestrator-trait.php`, `includes/warmup/class-warm-page-pipeline-trait.php`, `includes/settings/class-settings-registration-trait.php`, `includes/settings/class-settings-rendering-trait.php`, `includes/settings/class-settings-validation-trait.php`, `includes/settings/class-settings-persistence-trait.php`, `includes/rest/class-rest-cache-trait.php`, `includes/rest/class-rest-routes-trait.php`, `includes/rest/class-rest-schemas-trait.php`, `includes/cli/class-wp-cli-cache-trait.php`, `includes/admin/js/dashboard-application.js`, `includes/admin/js/help.js`, `includes/admin/js/jobs.js`, `includes/admin/js/lifecycle.js`, `includes/admin/js/settings.js`, `includes/admin/js/ui.js`, and `includes/admin/js/warmup.js`. = 2.59.10.06 = * Add a short-lived HMAC-signed same-site LiteSpeed control endpoint with expiry validation and atomic replay protection. The endpoint emits the native `X-LiteSpeed-Purge` response only after the signed request is accepted and returns an explicit UltraCache acknowledgement to the blocking caller. * Purge the native LiteSpeed site cache by the stable UltraCache site tag after full and update-driven page-cache invalidation, avoiding a server-wide `*` purge for UltraCache-owned HTML. * Connect every `ultracache_after_purge_urls` event to exact affected-URL tag invalidation. Local URLs are normalized, query strings and foreign hosts are rejected, duplicates are coalesced, and requests are split into bounded batches of 20 targets. * Keep native invalidation on the blocking signed response path so the LiteSpeed purge response has completed before the next warm/refill stage can run; retain the existing official LiteSpeed WordPress purge-all transport when UltraCache native LiteSpeed HTML caching is not enabled. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/class-rest-api.php`, `includes/bootstrap/class-bootstrap-trait.php`, `includes/integrations/litespeed/class-litespeed-transport-trait.php`, `includes/integrations/litespeed/class-litespeed-control-trait.php`, `includes/runtime/class-runtime-cache-services-trait.php`, `includes/maintenance/class-update-cache-invalidation-trait.php`, `includes/rest/class-rest-routes-trait.php`, `includes/rest/class-rest-litespeed-trait.php`, `includes/admin/js/dashboard-application.js`, and `includes/admin/js/help.js`. = 2.59.10.05 = * Add an opt-in native LiteSpeed HTML Cache setting with a managed `.htaccess` block placed before application rewrites. The block enables public cache lookup while bypassing non-GET/HEAD requests, query strings, authorization, unsafe cookies, configured dynamic paths, and file-like requests. * Publish eligible UltraCache HTML with `X-LiteSpeed-Cache-Control` using the existing Fresh TTL, stable site and exact-URL tags, and `X-LiteSpeed-Vary` values that match companion ingress rules for isolated `orig`, `webp`, and `avif` cache keys. * Extend Apache Static HTML Delivery responses with the same LiteSpeed TTL, site tag, and per-file image-bucket vary value; remove managed LiteSpeed rules on deactivation/uninstall and verify `.htaccess` writes inside the existing settings transaction. * Add the LiteSpeed HTML Cache dashboard switch, Help text, REST/settings mappings, activation diagnostics, and settings-profile preservation. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/core/html-variant-functions.php`, `includes/core/filesystem-guards.php`, `includes/engine/class-engine-litespeed-response-trait.php`, `includes/engine/class-engine-response-headers-trait.php`, `includes/engine/class-engine-storage-trait.php`, `includes/class-ultra-cache-engine.php`, `includes/server/class-server-rules-trait.php`, `includes/settings/class-settings-registration-trait.php`, `includes/settings/class-settings-rendering-trait.php`, `includes/settings/class-settings-persistence-trait.php`, `includes/rest/class-rest-schemas-trait.php`, `includes/lifecycle/class-plugin-data-cleanup-trait.php`, `includes/admin/js/dashboard-application.js`, `includes/admin/js/help.js`, and `includes/admin/js/settings.js`. = 2.59.10.04 = * Separate LiteSpeed/OpenLiteSpeed web-server detection from confirmed cache activity. A LiteSpeed server name alone no longer marks the cache layer as enabled or flushable; observed `X-LiteSpeed-Cache`/`X-QC-Cache` headers are recorded independently from the available purge transport. * Add a dedicated LiteSpeed transport trait and prefer the documented `litespeed_purge_all` WordPress hook. Use the native `X-LiteSpeed-Purge` response transport only after `X-LiteSpeed-Cache` evidence, or `X-QC-Cache` evidence combined with a LiteSpeed origin; retain older class/function APIs as final compatibility fallbacks. * Revalidate the LiteSpeed transport when a purge runs, bump the external-cache detection schema, and stop reverse-proxy diagnostics from classifying a bare LiteSpeed `Server` header as active page cache. * Update dashboard and Help text to describe the confirmed transport requirements accurately. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `includes/integrations/litespeed/class-litespeed-transport-trait.php`, `includes/integrations/varnish/class-varnish-diagnostics-trait.php`, `includes/runtime/class-runtime-cache-services-trait.php`, `includes/admin/js/cache.js`, `includes/admin/js/dashboard-application.js`, and `includes/admin/js/help.js`. = 2.59.10.03 = * Finalize browser-observed LCP learning only from a five-second timer after page load; user input, scrolling, visibility changes, pagehide, and freeze no longer submit the current candidate early. * Add one saved Manual LCP selector field inside every discovered URL detail panel, accepting CSS selectors, plain IDs, or image URL/fragments and refreshing that URL after changes. * While LCP Frontend Discovery is enabled, ignore the General Inclusions Manual LCP selector and use only the per-URL selector for each discovered page; when discovery is disabled, the existing general setting remains effective. * Changed files: `ultracache.php`, `readme.txt`, `README.md`, `changelog.txt`, `languages/ultracache.pot`, `assets/js/lcp-observer.js`, `includes/admin/css/sections.css`, `includes/admin/js/api.js`, `includes/admin/js/dashboard-application.js`, `includes/admin/js/dashboard-diagnostics-ui.js`, `includes/diagnostics/class-lcp-diagnostics-trait.php`, `includes/engine/lcp/class-lcp-detection-trait.php`, `includes/engine/lcp/class-lcp-html-rewrite-trait.php`, `includes/engine/lcp/class-lcp-observation-storage-trait.php`, `includes/engine/lcp/class-lcp-observation-trait.php`, `includes/rest/class-rest-lcp-diagnostics-trait.php`, `includes/rest/class-rest-routes-trait.php`, `includes/settings/class-settings-persistence-trait.php`, `includes/lifecycle/class-plugin-data-cleanup-trait.php`, and `uninstall.php`. = 2.59.10.02 = * Finalize browser-observed LCP learning on first user input, page visibility loss, pagehide/freeze, or a 30-second idle fallback instead of submitting a provisional candidate 2.5 seconds after window load. This keeps late video frames eligible to become the final desktop/tablet/mobile LCP winner before two-of-three locking. * Classify `