Latest stable release
Original notes
VonCMS v1.26.9 "After Hours"
VonCMS v1.26.9 includes the complete v1.26.8 and v1.26.9 maintenance set, covering public discovery, navigation, media search, shared-host stability, request hardening, lightweight cache performance, extension compatibility, and source scanner hygiene.
v1.26.9 Highlights
- Hardened structured request handling across login, registration, page saving, comments, RSS, sitemap, and OTA endpoints.
- Malformed arrays and compound values now fail safely before reaching PHP string functions.
- Login and registration throttling now uses atomic, isolated rate-limit buckets.
- Valid anonymous post-list and settings cache hits return before loading configuration, PDO, or database schema checks.
- Cold cache rebuilds and cache purges now share coordinated locking to prevent duplicate database work and stale cache restoration.
- Security logging and central API error handling now contain malformed data and unexpected
Throwablefailures safely. - Upload protection is aligned across packaged, fresh-install, integrity-check, and repair flows.
- Media variant paths reject traversal attempts, encoded separators, and unsafe control characters.
- Removed an obsolete WordPress remote-image transport while preserving the bounded cURL importer.
- RSS and sitemap query offsets are bounded against unnecessarily deep database work.
- Theme and plugin development documentation now defines required compatibility, security, routing, SEO, media, and packaging contracts.
- Optional Node AI routes now parse Bearer credentials through a linear parser while retaining exact constant-time token comparison.
- Updated OpenRouter SDK, TipTap, and compatible type dependencies.
- Final npm audit reports zero known vulnerabilities.
v1.26.8 Highlights
- Public search now persists through
?search=URLs on supported themes. - Direct search links, bookmarks, reloads, and browser navigation restore the search query correctly.
- Media Library, Featured Image, and TipTap Insert Media now use responsive debounced search with stale-response protection.
- All six bundled themes expose real crawlable links while retaining normal SPA navigation.
- Homepage SSR, no-JavaScript output, and CollectionPage schema now expose the latest ten published articles.
- Added a responsive text-first no-JavaScript reading layout for homepage, category, and single-content routes.
- Social metadata now shares one validated image priority chain across SSR and VonSEO.
- Favicon, social-image, and system-image uploads receive stricter MIME and extension validation.
- Related Posts now uses stored keywords, normalized category matching, and effective scheduled publish time.
- Public article cards, profiles, Related Posts, schema, and llms.txt now share consistent effective publish timestamps.
- RSS remains available through its standard endpoint and head discovery link but is no longer listed as a sitemap document.
- Improved local AI summary extraction for thin, medium, and long articles.
- Improved the basic AI writing recipe for Malaysian Malay, supplied facts, quotations, and inverted-pyramid news structure.
- Fixed PHP 8.2 null-sanitizer and missing-row warnings.
- Fixed temporary public-cache cleanup warnings on shared hosting.
- Added deterministic page-list ordering and improved public navigation projections.
- Refreshed Vite, OpenRouter, TipTap, DOMPurify, Lucide, and compatible dependency packages.
Upgrade Notes
- Back up the site and database before upgrading.
- Use
VonCMS_v1.26.9_Deploy.zipfor production deployment or OTA upgrades. - Normal Deploy and OTA upgrades do not require replacing an existing live
von_config.php. von_config.sample.phpis provided as the current reference for new installations and optional configuration modernization.- Existing uploads, data, configuration, backups, and live
.htaccessfiles remain protected during OTA activation.
Verification
- npm dependency review: clean.
- npm audit: 0 vulnerabilities.
- TypeScript typecheck: passed.
- Production build: passed.
- Full integration smoke gate: passed.
- PHP 8.3 workspace lint: 101/101 passed.
- Deploy ZIP PHP lint: 101/101 passed.
- Source ZIP PHP lint: 103/103 passed.
- GitHub CodeQL workflow: passed.
SHA256 Checksums
VonCMS_v1.26.9_Deploy.zip
83969E8E272819596CF7B575B9DDC224725352FF1E2AA82E4F88A0692606E66C
VonCMS_v1.26.9_Source.zip
58E4944317381EE5A149801B2730EF4D546DDA628D4D3495792415A5481E1667