v2.8.7
More Ways to Buy, Secure, and Manage Your Sites
This release brings new purchasing APIs, stronger site security, safer Git workflows, and more flexible caching across xCloud. It includes 42 merged changes since v2.8.6.3, together with the supporting platform and database updates.
Release at a Glance
- 5 major new features
- 5 customer-facing improvements
- 23 bug fixes
- 42 total merged changes since v2.8.6.3
π₯ New Features
Purchase Services through the Public API
Purchase mailbox services, mail delivery, and xCloud-managed servers programmatically for easier automation and integration with your existing workflows.
Site Security Pro
Understand and strengthen your WordPress security with a security score, protection-health insights, CAPTCHA and network controls, and an expanded hardening suite.
Refunds & Credits Workspace
A dedicated administrative workspace makes it easier to review and manage refund requests, account credits, and related actions.
Staging Environments for Git Sites
Create separate production and staging environments for Git-based sites, so changes can be tested safely before deployment.
xSpeed Cache Integration
Use xSpeed Cache as a first-class page-cache provider, with integrated controls for activation, deactivation, purging, and Redis-backed object caching.
β¨ Improvements
- Safer database management β Databases currently used by a site or server are protected from accidental deletion.
- More informative Docker backups β Backup screens now display the provider, storage bucket, backup size, and the team member who started the backup.
- Better mobile usability β Deployment tables, site headers, add-site screens, and warning banners now work better on mobile displays.
- Consistent backup exclusions β Excluded paths are now synchronized correctly when backup settings are applied in bulk.
- More reliable cache controls β xSpeed Cache activation, deactivation, purging, Redis handling, and provider status are now clearer and more dependable.
π Bug Fixes
- Git deployments no longer overwrite non-empty destination directories, and interrupted clones can be retried safely.
- Private package checkout now correctly applies eligible access-key coupons.
- Cloudflare Enterprise Origin CA certificates are now assigned to the correct xCloud origin hostname, preventing TLS 526 errors.
- Refund receipts now show the amount that actually settled, including partial-refund and duplicate-webhook scenarios.
- The βreboot requiredβ alert is displayed correctly on server pages again.
- Git sites no longer reuse server-provisioning keys as repository deploy keys.
- Vultr provisioning now verifies the selected SSH key before creating an instance.
- Incremental SQL cleanup now preserves valid backup chains instead of relying only on file age.
- Git deployment webhooks now handle invalid site identifiers and missing secrets safely.
- OpenLiteSpeed now blocks access to sensitive dotfiles consistently on both new and existing sites.
- βContinue Setupβ now opens the provider and plan originally selected by the customer.
- Redis installation now records the correct version and preserves an existing PHP Redis extension.
- Heartbeat checks no longer repeatedly attempt SSH connections to known-unreachable servers.
- Backup restore now lists eligible destination servers correctly.
- LTD and provider conversions now retain the correct recurring price and billing state.
- Updated default blueprints now add missing plugins without overwriting team customizations.
- OpenLiteSpeed configuration checks no longer treat harmless warnings as failures.
- nginx.org upgrades now work correctly on Ubuntu 22.04.
- OpenLiteSpeed TLS repair now confirms that the placeholder certificate has been replaced.
- OpenClaw and Paperclip servers now use Node.js 24 by default.
- Large Git-provider lists no longer cause memory errors while sorting.
- Nginx Helper settings are now written and activated correctly for WordPress Multisite.
- Starting a manual Docker backup no longer creates an unintended recurring schedule.