Improved security across the plugin, including how campaigns are searched, previewed and tracked, how form submissions and integrations are handled, and how visitor information is read.
Improved: your captcha secret keys and MaxMind license key now stay on the server and are no longer shared with the campaign editor.
Improved: the {user.*} Smart Tag now only returns profile details such as name and email.
Improved: stored integration credentials (MailChimp, Brevo, Klaviyo and others) get an extra layer of protection. Existing connections keep working.
Improved: visitor cookies now work correctly on sites served over plain HTTP.
Improved: IP and Geolocation conditions now detect a reverse proxy on your own network automatically. If your site sits behind a CDN that does not pass the visitor's address through to WordPress, the new fpframework/trusted_proxies filter lets you tell FireBox about it.
Improved: the Cloudflare Turnstile and hCaptcha setup notice in the campaign editor now also appears when only the secret key is missing.
Fixed: the Brevo integration failed to load your contact lists.
Improved compatibility with WP Rocket: FireBox now automatically excludes its files from Delay JavaScript Execution, minification, and Remove Unused CSS, so campaigns keep working without adding manual exclusions in WP Rocket's settings.
Improved security: custom PHP in display conditions and PHP Scripts now runs only for campaigns whose author holds a dedicated "run PHP" permission. Administrators have it by default; other roles cannot run PHP unless you grant them the permission deliberately.
Improved security: custom JavaScript and custom CSS on a campaign now run only for campaigns whose author is allowed to add code. Administrators can by default; other roles cannot add custom code unless you grant them the permission deliberately. Custom CSS is also cleaned so it can't be used to inject anything other than styles.
Improved security: turning a campaign on or off from the campaigns list now checks that you have permission to edit that specific campaign, and only ever changes FireBox campaigns.
Improved security: values taken from the current page address and the referring page now have any code removed before they appear inside a campaign, so a crafted link can't inject content into your campaigns.
Improved security: duplicating a campaign now checks you have permission to edit it, and the copy belongs to whoever created it.
Added: a limit on how many times the same visitor can submit a form each minute, so a single visitor can't spam your submissions list.
Improved Multisite support: FireBox now sets itself up on every site of a network, including sites added later, so campaigns, analytics and permissions work without visiting each site first.
Improved Multisite support: campaigns on different sites of a network no longer share cookies, so closing a campaign on one site can't hide a campaign on another.
Improved Multisite support: removing FireBox from a network now clears each site's data according to that site's own "Keep data on uninstall" setting, and deleting a site removes its FireBox data with it.
Improved: cookies now follow your site's WordPress cookie settings, so campaign frequency and analytics keep working on sites that share cookies between www and non-www addresses.
Improved how integration credentials (MailChimp, Brevo, Klaviyo, and others) are stored.
Improved the handling of imported campaigns so their content is cleaned up before it is saved.
Improved how Rating field values are shown in the Submissions list.
Improved: campaigns now use their own set of permissions, so you can give someone access to campaigns without giving them access to all your posts.
Improved the accuracy of conversion and analytics tracking by ignoring invalid or duplicated data.
Improved: connecting or disconnecting an integration now requires administrator access.
Improved how the submissions REST API key is sent and verified.
Improved security when FireBox checks for updates: it now confirms it is really talking to the FirePlugins license server before downloading anything.
Improved: WordPress now offers the auto-update option for FireBox in the Plugins list, instead of saying auto-updates are not available.
Improved privacy: FireBox no longer tells WordPress.org about itself when WordPress checks for plugin updates.
Improved the handling of the {fbExpr} expression feature.
Improved the handling of redirects and messages shown after a form is submitted.
Improved the delete and duplicate actions in the campaigns list.
Improved: page speed for campaigns with custom JavaScript no longer hold up the rest of the page while FireBox loads. Custom code now runs right after your campaigns are ready.
Improved: page speed when serving multiple FireBox campaigns on same page.
Improved: page speed by loading only the animations your campaign uses, instead of the whole animation library. This cuts about 69KB from every page a campaign appears on.
Fixed: page slide campaigns could appear full-height and outside their slide area on some sites.
Fixed: an error that could occur while FireBox was updating itself.
Added: a new campaigns list with ability to sort, filter, and manage your campaigns in bulk.
Improved security of visitor cookie handling on campaigns using a daily, weekly, or monthly display frequency.
Improved security of Phone Number values shown in the Submissions list and in admin notification emails.
Improved security of the {post.} and {cookie.} Smart Tags, which now strip HTML from their values, matching the {querystring.*} Smart Tag.
Improved: Compatibility of YouTube shorts in the Video block.
Improved: replaced PHP sessions with cookies on the front-end, restoring full-page caching compatibility and fixing the Site Health "active PHP session" warning and REST API loopback timeouts.
Improved: cookies are now only set when a campaign actually needs them (e.g. Pageviews condition).
Improved: the front-end script now loads deferred for faster page rendering.
Improved: campaign and settings lookups are now cached on sites with a persistent object cache.
Improved: WordPress 6.3 compatibility.
Improved: campaign revenue now excludes refunded WooCommerce and Easy Digital Downloads orders, matching your shop's own analytics. Use the firebox/revenue_attribution/order_total filter to restore gross revenue.
Improved: hardened display-condition, conversion-tracking, geolocation, upgrade, and license handling against unexpected or malformed data.
Fixed: MailChimp integration removed a subscriber's existing tags and interest groups even when "Replace Tags?" was turned off.
Fixed: a campaign containing a Heading, Button, or Paragraph block set to a Google font could fail to render on the front-end in some saved or imported campaigns.
Fixed: submitting a form with an optional Phone Number field, or editing a submission with malformed data, could trigger a PHP error.
Fixed: exporting campaigns via a malformed request could trigger a PHP error before the security check.
Fixed: corrected a build marker in the upgrade routine that could mis-package the Free, Basic, and Growth builds.
Fixed: the Phone Number field appeared unstyled in the block editor due to missing stylesheet.
Fixed: the Performance chart kept a Weekly or Monthly grouping selected after switching to a shorter timeframe that no longer supports it, now falls back to Daily automatically.
Fixed: YouTube videos in the Video block failed to load in the block editor preview with "Error 153".
Fixed: a {cookie.*} Smart Tag referencing a cookie that was not set could blank out the campaign's content.
Removed: the mini onboarding appearing after the first install.
Added: Revenue Attribution system to track the total revenue generated by your popup campaigns (integrates with WooCommerce and Easy Digital Downloads).
Added: View-Through Revenue tracking that measures revenue from visitors who view your campaigns and purchase later without directly converting.
Added: Conversion-Through Revenue tracking that measures revenue from visitors who view campaigns, convert through them, and then make purchases.
Added: Sales Funnel Analysis to visualize the complete customer journey through the steps: views > clicks > conversions > purchases.
Added: Click tracking for buttons, links, and form input fields to provide deeper interaction insights.
Added: Smart Tags are now replaced in Actions > Custom Javascript section.
Improved: Performance chart now displays key metrics above the chart.
Improved: Display Conditions "Set Custom Rules" button with clearer icon and improved labeling.
Updated: Analytics Conversion Rate and Revenue colors.
Updated: Analytics Revenue chart type to a Bar chart.
Fixed: PHP 8.2 deprecation notices.
Fixed: Embed Campaigns wouldn't execute Actions.
Fixed: Embed Campaigns wouldn't execute Advanced Panel > Custom Javascript in some cases.
Fixed: Embed Campaigns wouldn't refresh when selecting a different campaign in the editor.
Fixed: A rare issue where editing display conditions that include a text repeater (such as URL, Referrer, etc…) would throw an error.
Fixed Javascript errors in campaign editor preventing specific settings from working properly in certain circumstances.
Fixed Design Panel > Image as Background would appear enabled when importing a template.
Fixed EDD/WooCommerce Amount in Cart condition wouldn't initially display "Exclude Shipping Cost" and "Exclude TAX/VAT" toggles until you select the subtotal and then total type.
Fixed: Compatibility issue with Elementor where popup content would be incorrectly replaced with Elementor page content when viewing Elementor-built pages.
Enhancement: Immediately show the popup to the user when Behavior > Closing Behavior > "If the user closes the campaign" is set to "keep showing the campaign".
Fixed: Certain blocks aren't working as expected in edge cases.
Fixed: Floating Button may not appear in correct position.
Fixed: Opening Sound may play more than once after re-opening the popup.
Fixed: Campaign settings aren't saved due to a PHP error related to the Hummingbird plugin when trying to clear the cache.
Fixed: Improved the appearance of Embed campaigns in the gutenberg editor.
Fixed: PHP 8 deprecation notice "Creation of dynamic property SmartTags::$isPro is deprecated".
Removed: Depreacted "FireBox Campaigns" section from the FireBox and Core Buttons/Image blocks. These settings have been moved to the new FireBox panel.