2.3.8
First official public release
= 2.3.9 =\
Fixed minor theme related bugs
= 2.3.10 =\
Fixed minor theme related bugs
2.3.11
Fixed issues with "Set Social" on the backend
2.3.13
Added Twitter handle for sharing
2.3.16
Added Twitter handle for sharing
Fixed upload bugs
2.3.19
Fixed category tag issues
2.3.20
Fixed memory upload issues
2.3.21
Fixed issues with social image share
2.3.23
Fixed issues with Style formatting
2.3.24
Fixed issues with Java Script - conflicts with newer versions
2.4.7
Made KBucket page micro tags visible to the search engine
Added short code capabilities to make it compatible for more themes
Changed how images are uploaded. Once an image is loaded from the server, it will stay, till changed by the server.
2.4.8
Solved issues with mobile display
2.6.1
Changed the URL structure to SEO friendly URLs.
2.6.3
Added a new template with the channels appearing in the side-bar
2.6.6
Added CSS tab for modifying look and feel of the KBucket page
2.6.7
Fixed issues with image upload
2.6.16
Updated Mobile display of posts. Now you see the whole description while in Mobile viewing. This helps with our Botcopy integration.
2.6.22
Updated the version to work with the new Wordpress database, enhanced the RSS feeds and added more fields for our Chatbot CMS solution and changed how the cards display content.
2.7
Updated the tag and image edit features. Also made the plugin compatible with PHP 8.0
2.7.4
Added a new theme for the KBucket page.
Added the ability to edit and replace images directly on the page
Updated the payment gateway
2.7.6
Ability to add description for each channel
2.7.7
Fixed issue with camera icon
2.8.0
Fixed minor issues and crated a link back to our website
2.9.0
Added a sync feature to sync Kurator files with KBucket
2.10.0.1
Fixed bugs with the sync feature
2.11.7
Fixed issues with Sync, improved the uploading process to only update what has changed. Much faster sync process.
2.11.9
Fixed an issue with a log file that needed to be deactivated. It was slowing down access to plugin on the back end.
2.12.1
Added styles option for customizing the look & feel of the content tags and post items. Updates to image upload and sync feature.
2.12.2
Fixed a compatibility bug with Wordpress version 6.1.1
2.13.9
Added widgets to embed content from KBucket via short code anywhere on your website.
2.13.11
Added a Slider widget via short code
2.13.18
Updated the look & feel of the embed widgets and added the readme button to the posts
2.14.3
Updated php to support 8.0, and added capability to play YouTube videos directly on the page.
2.14.5
Updated PHP to support 8.3, fixed issues with theme display, changed captions for videos, added Facebook share button
3.1.3
Fixed incompatibility with Astra themes, introduced new widget theme
3.1.6
Fixed compatibility issues with JS and minor bug fixes
3.1.9
Added new option to display popups (Left, Center, Right)
4.1.1
Fixed issues with popup text formatting and image alignment
4.1.5
Fixed security issue with $_SERVER[‘REQUEST_URI’]
4.1.6
Fixed Security issue with YouTube API
4.2.4
Applied prepare condition with sql query
4.2.5
Fixed a widgets broken issue.
4.2.6
Fixed a formatting of the posts on share popup.
5.0
Changed the yearly license to a free license and fixed the upload workflow
5.2
Improved structured data implementation by setting the correct schema @type for content items.
5.2.1
Fixed sync-by-URL failing with "File empty" on larger XML exports. The staging
step now writes the downloaded file to disk under /uploads/ instead of an
AES-encrypted blob in wp_options, which silently truncates on MySQL servers
whose max_allowed_packet is below the encrypted file size (~33% larger than
the raw XML due to base64). Removes a fixed-key/no-IV "encryption" pass that
provided no real security. Backward-compatible read fallback for any sync
that was mid-flight when the patch was applied.
5.2.2
Tested with WordPress 7.0. Pinned the Stable tag to an actual version
(previously "trunk") so the
WP.org plugin page serves a known-good build
rather than whatever happens to be in trunk.
5.2.3
Fixes "YouTube video is broken or unavailable." appearing in place of videos
that are perfectly fine. The share modal was refusing to output the embed
unless a YouTube Data API lookup succeeded first, and installs that have not
set their own API key share one bundled key whose daily quota is regularly
exhausted - so a 403 from Google read to visitors as a broken video. The embed
is now rendered from the video id alone and never depends on that lookup; the
API is used only for the optional views/likes/channel panel. That lookup is
also now made once per view instead of twice, cached for 12 hours (failures
cached for 15 minutes), given a 5 second timeout, and issued through
wp_remote_get so it works on hosts with allow_url_fopen disabled. The settings
screen now explains how to add your own key. Also hardens the id parser
against ?t=/&list=/# suffixes and tolerates videos with likes or view counts
hidden.
5.2.4
Fixes the scheduled upload not running at the interval you selected. The
scheduler runs on every front-end page load, and it was clearing and
re-creating the cron event each time, discarding WordPress's record of when
the event was next due. A site set to "Every 1 hour" would instead sync at
unpredictable intervals, often 14 to 21 hours apart. The event is now created
once and only rebuilt when the interval actually changes, so hourly means
hourly. Also clears the schedule when auto upload is switched off or set to
Manual, instead of leaving an orphaned event behind.
5.3.0
KBucket now inherits your theme instead of imposing its own look.
PLEASE READ - THIS CHANGES HOW YOUR GALLERIES LOOK. Until now the plugin
hard-coded its own palette and typography (Raleway, coral headings, white
panels) into every page it rendered, and set much of it with !important, so
the only way to restyle KBucket was to fight it with more !important. That is
also why KBucket looked out of place on dark themes, and why its popup stayed
white no matter what your theme did.
Colours, fonts and backgrounds are now CSS custom properties. On the front end
they are left undefined on purpose, so KBucket's headings, body text and panels
take the font, text colour and background of whatever theme you are running.
On most sites this simply makes the galleries and the article popup look like
the rest of the site. On sites that were built around KBucket's old colours,
the galleries will change appearance after updating.
To pin the previous look, or any palette you like, set the tokens in your
theme. No !important required:
.kb-wrapper, #kb-wrapper, #facebox .content {
--kb-font: Raleway, sans-serif;
--kb-bg: #ffffff;
--kb-bg-alt: #f6f6f6;
--kb-fg: #333333;
--kb-fg-muted: #828282;
--kb-accent: #e64d47;
--kb-accent-hover: #e76c67;
--kb-border: #dddddd;
}
48 presentational !important declarations were removed so your theme can win
the cascade normally. The wp-admin screens are unaffected - the old palette is
still applied there. Note that if you previously restyled KBucket with
!important overrides, those still win; a rule written for the old markup may
now be redundant, and an overly broad one (for example setting overflow on the
popup body) can still cause problems.
5.3.1
Fix: meta descriptions and canonical links are no longer removed from
non-KBucket pages.
KBucket's workarounds for Yoast SEO on its own hub pages were being applied
to every page of the site. Yoast's meta description and canonical link were
suppressed site-wide, and WordPress's own canonical link was removed from
every front-end page, which also affected sites running no SEO plugin at
all. All three now apply only on KBucket pages.
5.3.2
Fixes the SEO tags KBucket writes into on its own item pages. Yoast and
WordPress's canonical are deliberately removed on these pages, so KBucket's own
tags are the only signals search engines and social scrapers get.
- Adds pointing at the item's clean URL, built from the
site's configured home URL, with no query string and the site's own trailing
slash convention.
- og:url now uses that same canonical URL. It previously used the raw request
URL, hard-coded to http:// and carrying any query string, so a shared link
could report a different URL than the page it came from.
- Descriptions are cleaned up: leading transcript timestamps such as "(00:04)"
or "[0:05]" are stripped, whitespace is collapsed, and the text is truncated
on a word boundary at about 155 characters instead of mid-word at 107.
- Each og: tag is output once. The duplicate block using
prefix="og: http://ogp.me/ns#" has been removed.
- og:image:width and og:image:height are output only when the real dimensions
are known, instead of always reporting 0, and og:image:type is derived from
the file extension instead of always claiming image/png.
- twitter:card is now summary_large_image instead of photo.
- Removes the Cache-Control, Pragma and Expires meta http-equiv tags.
5.3.3
Removes AddThis. Oracle shut the service down on 31 May 2023, so every
AddThis button in KBucket has been inert since then and the plugin was still
loading a script from
s7.addthis.com on the front end.
- The addthis_widget.js enqueue is gone, along with the bundled copy of the
script, the refreshAddthis() helpers in four JavaScript files, the AddThis
event handlers and the addthis_share passthrough blocks.
- The share panel's Email button is now a plain mailto: link carrying the
item's title and URL, with the same icon. It previously did nothing.
- The StumbleUpon button has been removed. StumbleUpon closed in 2018. The
copy-citation button now reads the item URL from its own data-url attribute
rather than from the StumbleUpon badge.
- Facebook, X, LinkedIn and Pinterest are unchanged. They are ordinary links
and were never AddThis-powered.
CSS class names such as addthis_toolbox_custom are retained because the share
panel's layout still hangs off them.
5.3.4
Housekeeping. Deletes templates/backupds/, an old backup copy of two
templates that no code loaded. It still carried the AddThis and StumbleUpon
markup removed in 5.3.3, so it shipped dead third-party code to every site.
No functional change.
5.3.5
Security and front-end performance fix. Please update.
Security: the AJAX endpoints that set an item's thumbnail checked neither a
nonce nor a capability. Because they are wp_ajax_ actions, any logged-in
user — including a subscriber who self-registered — could change any item's
thumbnail to any URL, and could write post meta onto any post ID by passing
it as the attachment. Both endpoints now verify a nonce, require the
upload_files capability, validate the item id and reject any image URL that
is not http or https or that does not belong to a real attachment. The
camera control is now shown only to users who hold that capability; it was
previously rendered for every logged-in user.
Performance: every front-end page loaded the whole WordPress media editor —
Backbone, the media views, the uploader and the media players — for every
visitor, including logged-out ones, so that an administrator could change a
thumbnail. Those scripts are now loaded only for users who can use the
control, and only on pages that actually render it. Anonymous visitors load
none of it.
5.3.6
Security fix. Please update.
Four leftover debug entry points ran on the init hook and answered any
request, from anyone, on any URL of the site. No login was required.
Three of them had no caller anywhere in the plugin and have been removed
outright: two that triggered the content sync and image staging by hand, and
an image-parser tester. The image tester was the serious one. It checked the
file extension of the URL it was given but only printed a warning and carried
on, so it would fetch a remote file and write it into the uploads directory
under an attacker-chosen extension. It also made the site fetch any URL it
was handed, including addresses on the host's own network.
The fourth prints the auto-upload log and is reached from the Full Log link
on the KBucket admin Upload tab. It now requires an administrator and a valid
nonce, and returns 403 otherwise. Previously anyone could read the log by
appending the parameter to any URL.
The scheduled sync and the normal image import are unaffected: they run
through kb_activate_auto_upload_kbucket(), which already applies the
extension whitelist correctly and is unchanged.
5.4.0
Front-end performance. KBucket now loads only the assets a page actually
needs, and loads them later.
- Masonry and imagesLoaded were enqueued in the head of every page on the
site, whether or not it showed any KBucket content. They are now pulled in
only by layouts that use them, so a carousel page no longer downloads
masonry at all.
- jQuery UI (core, mouse, draggable, droppable) is no longer enqueued on the
front end. Nothing there used it.
- The Font Awesome 4.7 stylesheet from maxcdn is no longer loaded. The slider
arrows now use current Font Awesome class names. Sites that have no Font
Awesome of their own can restore it with:
add_filter( 'kbucket_load_font_awesome', '__return_true' );
- KBucket's scripts now load deferred from the footer on WordPress 6.3 and
above, instead of blocking the parser.
- Pages with several widgets printed the kbObj data, an inline script and an
inline stylesheet once per widget. Each is now emitted once.
- Item images carry real width and height, lazy loading below the fold, and
async decoding, so they no longer shift the layout as they arrive. The
ImageObject microdata reports the measured size instead of a fixed 500x500.
- Minified builds of the widget script, facebox and the stylesheet ship with
the plugin and are used unless SCRIPT_DEBUG is on.
5.4.1
Fixes two faults in the widget JavaScript that stopped carousels from
starting and left YouTube videos playing after the popup was closed.
The widget script patched Masonry's prototype at the top of its startup
routine, before deciding which layout to build. From 5.4.0 masonry is no
longer loaded for carousel and slider layouts that never use it, so that line
threw and everything after it was abandoned: slick never initialised, and the
carousel rendered as a plain grid. Those patches now run only when Masonry is
actually present.
The same routine also used Underscore's _.debounce for its resize handler.
Underscore was never declared as a dependency - it happened to be on the page
because the plugin loaded the WordPress media editor everywhere, which 5.3.5
stopped doing. It is replaced with a small local debounce, so the code after
it now runs: that includes loading the YouTube IFrame API, without which the
player object was never created and closing the popup could not stop the
video.
5.4.2
Hardening, no visible change. The remaining places where the widget and hub
scripts assumed Masonry or imagesLoaded were on the page now check first.
These libraries are only loaded for layouts that use them, so a missing one is
normal rather than exceptional. An unguarded reference throws and abandons the
rest of the enclosing function, which is how the carousel broke in 5.4.0. The
checks mean a layout that cannot run simply does not run, instead of taking
unrelated features down with it. Where imagesLoaded alone is missing, the grid
now lays out immediately rather than not at all.
5.5.0
Crawl and indexing control for the URLs KBucket generates. NOT YET VERIFIED
ON A RUNNING SITE - test on staging before updating a live install.
- Tag, related-tag, author and publisher listings, pages after the first, and
sort/order/format/share/mtag variants now return 'noindex, follow'. They
stay crawlable so search engines still reach item pages through them. Item
pages and the first page of each category and collection are unchanged.
- A category and collection that both exist but do not belong together now
return 404. They previously rendered, because only each half was checked,
and were then 301'd to the KBucket home - which kept them indexed.
- Mixed-case KBucket URLs redirect once to the lowercase https form.
- The legacy /kc/{id}/ and /kb/{id} URLs resolve to the item's current
address, or return 410 when the item no longer exists. They previously
rendered a collection listing under an item URL.
- The category menu query is cached per request instead of running about a
dozen times per page.
5.5.1
The 5.5.0 crawl and indexing rules now ship switched OFF. Installing this
version changes nothing for visitors or search engines until you opt in with
define( 'KB_SEO_ENFORCE', true );
in wp-config.php. A second constant, KB_SEO_DEBUG_TOKEN, makes the plugin
report what the rules WOULD do for any URL - as a response header, with no
change to the page - so the decisions can be checked against real URLs before
anything takes effect.
5.6.0
Item pages now render server-side. Every KBucket item already had its own URL,
/kbucket/{category}/{collection}/{slug}/, but that URL served the whole
collection listing and relied on JavaScript to open the item in the modal, so
search engines and AI crawlers never saw the item's full description. The URL
now renders the item itself - title, author, publisher, date, the embedded
video, the full description or transcript with timestamped section headings,
tags, a link to the source and a short "More in this collection" list - plus
VideoObject (or Article) JSON-LD including the transcript. The modal no longer
auto-opens on these pages; on listings it behaves exactly as before.
KBucket pages had no tag at all whenever Yoast SEO was active. They now
get one, and item pages are titled after the item.
Carousel and grid widget cards link to the item page instead of to YouTube, and
image cards show the title and a "Read the transcript" link under the
thumbnail. Clicking the thumbnail still opens the same modal.
New KBucket XML sitemap: /kbucket-sitemap.xml under Yoast SEO, or
/wp-sitemap-kbucket-1.xml with WordPress core sitemaps.
5.6.1
Sync by URL fixes. The downloaded file is now staged in
wp-content/uploads/kbucket/ instead of inside the plugin folder, so updating or
replacing the plugin mid-sync no longer deletes it. A missing staged file no
longer aborts an image import that is already under way ("File empty" followed
by missing images). Failed downloads now log the reason (curl error or HTTP
status), use timeouts, and wait a minute before retrying instead of retrying on
every page view. Only one sync runs at a time.
5.6.2
Carousel and grid image cards: the title under the thumbnail now opens the same
modal as the thumbnail, and the separate "Read the transcript" link is gone.
The title still links to the item page, so search engines and AI crawlers keep
reaching the full description. Caption and item-page sizes are set in px, so themes that set
a small root font size no longer shrink them.
5.6.3
Scheduled sync safety net. The hourly, 3-hourly and daily syncs only run when
WordPress cron runs. On hosts that disable WP-Cron and drive it from a server
cron job, a broken server job silently stopped every sync. Now, when the
scheduled sync is more than an hour overdue, the next front-end page view runs
it - after the page has been sent to the visitor on PHP-FPM and LiteSpeed - and
moves the schedule forward so only one visitor triggers it. The sync log notes
when this happens.
5.6.4
Performance: KBucket no longer regenerates WordPress's rewrite rules on every
page load, which also wrote the rewrite_rules option to the database on every
request. The rules are now regenerated once - on activation, after a plugin
update, or when the KBucket page's slug changes.
5.6.5
Images and accessibility. Removed a hidden placeholder publisher logo on every
card (src="/", no alt text) that also made browsers fetch the page itself as an
image. The pop-up's loading image and close button, the pop-up image for
non-video items, the citation button and the thumbnail-change button now have
descriptive alt text or accessible names.
5.6.6
WordPress.org release of the 5.6 series. The sync download now uses the
WordPress HTTP API instead of raw cURL, with the same timeouts, redirects and
logged error reasons. Tightened output escaping in the item and card
templates, and tested with WordPress 7.1.
5.6.7
Redirects for removed content. When a collection or item is deleted in Kurator,
its KBucket URLs now 301 instead of returning a 404: an item that moved goes to
its current page, a deleted item goes to its collection, and anything under a
removed category or collection (items, tag pages, pagination) goes to the
KBucket home collection. Disable with the kb_redirect_removed_urls filter.
Widgets with nothing to show now render nothing instead of "No result found".