Beschrijving
❤️ Uitstekende lidmaatschap plugin! Meer dan 15 jaar ervaring, ontwikkeling, releases… Nog steeds groeiend en vooruitgaand!
Start je ledenwinst! Bouw je tribe, verzamel je volgers, schrijf je studenten in, haal je klanten binnen!
💵 Geniet van de voordelen om herhaaldelijk betaald te worden voor toegang tot je site!
⭐⭐⭐⭐⭐ Briljant “Zo blij dat ik dit gevonden heb. Het werkt briljant voor onze behoeften… Hou van de naadloze integratie met PayPal. Alles wat we nodig hebben. Bedankt voor het maken van dit!” –zarverk2000
De beste manier om geld te verdienen met je WordPress site!
🤩 Verkoop onbeperkte lidmaatschappen, maak van gratis abonnees leden (abonnee naar lid s. 2 member s2Member), met een eenmalige betaling of terugkerende betalingen abonnementen.
Gemakkelijk en snel te gebruiken. bescherm de inhoud van je lidmaatschap in een ogenblik, en een ogenblik later ben je klaar om betalingen te ontvangen voor toegang voor leden!
Gemakkelijk te configureren en zeer flexibel. bescherm de hele site, niets, of slechts delen, zelfs ledenbestanden voor betaalde downloads!
👉 Installeer s2Member nu en verdien geld! 😀
⭐⭐⭐⭐⭐ Zoveel capaciteit & geweldige ondersteuning “Ik ben een beginner en kon het snel uitzoeken. Wanneer ik vastloop, ga ik naar het ondersteuningsforum en Cristian is er met een snel antwoord om me weer op weg te helpen.” –blueruck
⭐⭐⭐⭐⭐ De allerbeste plugin en ondersteuningsdienst “Geweldige plugin, netjes, eenvoudig te configureren en met interessante beveiligingsfuncties. een speciale vermelding aan Cristian wiens ondersteuning geweldig is, snel, duidelijk, zelfs voor gratis leden zoals ikzelf” -aflorarte
Vol met functies, maar niet verplicht om ze allemaal te gebruiken, alleen die je wilt. enkele ervan:
➡️ Member user levels and custom access capabilities
➡️ Membership content protection (post, page, category, tag, etc)
➡️ Protect anything served by WP (post types, URLs)
➡️ Member file protection (sell downloads)
➡️ Prevent member account sharing (limit IPs, simultaneous logins)
➡️ Protect accounts (limit failed login attempts)
➡️ Cool security/trust badge with your domain
➡️ PayPal Standard buttons for membership payments (more in Pro)
➡️ Automatic member access demotion at end of paid access time
➡️ Tracking software integration (affiliates, etc)
➡️ Email list services (Mailchimp, etc)
➡️ Notifications (signups, payments, etc)
➡️ Integrate with bbPress, BuddyPress for member communities
➡️ Compatible with any well coded theme (Elementor, Divi, etc)
➡️ Customize the WP login/registration look
➡️ Custom redirection after member login
➡️ Create custom profile fields for member accounts
➡️ Customize the user welcome email
➡️ And more!
👉 installeer en gebruik s2Member nu! 🤩
⭐⭐⭐⭐⭐ Zeer krachtige lidmaatschapsplugin “Deze lidmaatschapsplugin doet veel en heeft veel, heel veel configuratiemogelijkheden om te bereiken wat je wilt… ik kreeg extreem snelle en betrouwbare ondersteuning.” –liltrucks
⭐⭐⭐⭐⭐ Eenvoudig, compatibel, veilig en veelzijdig! “We zijn serieus onder de indruk van deze plugin en we raden het ten zeerste aan… We hebben geen enkele beperking gevonden in wat we proberen te bereiken… Een zeer soepel proces… Rechttoe rechtaan en gebruiksvriendelijk!… overtrof onze verwachtingen!” -tips4gamers
⭐⭐⭐⭐⭐ Uitstekende plugin “Deze plugin doet alles wat er op de doos staat. Het doet het goed… De functionaliteit is absoluut spot on. De ontwikkelaars/beheerders zijn ook actief en behulpzaam. helemaal een aanrader!” -richardfoley
⭐⭐⭐⭐⭐ Beste lidmaatschap plugin die ik heb gebruikt “Ik ben overgestapt naar s2 member ongeveer 3 jaar geleden na het proberen van een paar plugins. Ik vond deze andere plugins inflexibel en moeilijk te configureren … zeker het onderzoeken waard als je een robuuste lidmaatschapsoplossing wilt.” -rnwhalley
Je hoeft geen PHP-code te kennen of een ontwikkelaar te zijn. De enige code die nodig is, zijn copy-paste wp shortcodes, zoals voor de PayPal knoppen…. Maar is ook ontwikkelaar-vriendelijk om je installatie aan te passen indien gewenst.
Enkele redenen om s2Member Pro aan te schaffen
✅ Membership content dripping
✅ Stripe, PayPal Pro, Authorize.Net, ClickBank
✅ On-site one-step checkout with pro-forms (Stripe, PayPal, Auth.Net)
✅ Unlimited membership levels
✅ Membership renewal reminder emails
✅ Single-step member registration and payment with pro-forms
✅ Custom redirection after payment
✅ Coupon codes and gift/redemption codes
✅ Custom member offer redirections after login
✅ Pro API for new integrations
✅ Public members directory
✅ Members bulk import/update/exporter
✅ Multisite network support
✅ Login and registration forms to use in pages/posts
👉 Click here for more 🙂
⭐⭐⭐⭐⭐ The Best Membership Plugin “I have built with most Membership plugins and literally dozens using S2 Pro and I can tell you, bar none it is the best of all of them. Extremely powerful, anything you might want to do it can do… I highly recommend you try it out.” –antwoords
⭐⭐⭐⭐⭐ Excellent plugin & top support “We’ve used s2member pro on a few projects now & find it has met all our membership needs. Most impressive has been the support. Excellent communication, knowledgeable, friendly and super patient 🙂” –aaee6
⭐⭐⭐⭐⭐ Geweldige ondersteuning “Ik gebruik s2Member al 9 jaar… Geweldige ondersteuning van een high-end plugin en zeer gewaardeerd. Dit is een van de redenen waarom ik bij s2Member blijf. ondersteuning is altijd geweldig geweest!” –graphichome
⭐⭐⭐⭐⭐ Geweldige ondersteuning “Boven alles. ik gebruik deze plugin al meer dan tien jaar bij verschillende klanten en telkens als ik hulp nodig heb, hebben ze geholpen een oplossing te vinden.” –germars
Het gratis s2Member framework integreert met payPal site payments standard (ook gratis). Verkoop “Koop nu” of lidmaatschap toegang tot je site. Beperk de toegang tot rollen, mogelijkheden, berichten, pagina’s, of iets anders in WordPress.
Protect your WordPress Posts, Pages, Tags, Categories, URIs, BuddyPress, bbPress, and even portions of content within Posts, Pages, themes, plugins. Easily configurable and highly extensible. You can even protect downloadable files and streaming audio/video. Store files locally, or use s2Member’s integration with Amazon S3/CloudFront.
s2Member wordt bijna volledig aangedreven door WordPress shortcodes, waardoor geavanceerde integraties snel en eenvoudig zijn. Verkoop terugkerende (of eenmalige) abonnementen met veel flexibiliteit. Of verkoop “Koop nu” lidmaatschap toegang op verschillende manieren. Je kunt ook verkopen specifieke berichten / Pagina’s, verkopen lid toegang tot bestanden downloads, of verkopen leden custom capabilities die zeer configureerbare toegang tot specifieke delen van je inhoud.
👉 Installeer nu s2Member en begin geld te verdienen! 😀
Schermafbeeldingen







Installatie
LET OP: voor hulp met s2Member Pro, gebruik ons forum.
s2Member is zeer gemakkelijk te installeren
Net als elke andere normale plugin:
- Vanaf het WP beheerscherm Plugins nieuwe toevoegen scherm.
- Of upload via FTP de
s2membermap uit de zip naar je/wp-content/plugins/directory. - Activeer het vanaf de Plugins pagina in je WordPress beheer.
Hier is een snelstartvideo voor een eenvoudige basisopstelling om je op weg te helpen.
Zie ook
Gedetailleerde installatie/upgrade instructies.
Is s2Member compatibel met multisite networking?
Ja, vereist s2Member pro voor ongelimiteerd aantal sites. Nadat je multisite networking hebt ingeschakeld, met s2Member framework en pro actief, navigeer naar s2Member → multisite (Config) in het dashboard op je hoofdsite.
FAQ
LET OP: voor hulp met s2Member Pro, gebruik ons forum.
-
Is s2Member compatibel met multisite networking?
-
Ja, s2Member Pro voor ongelimiteerde sites is compatibel met multisite networking. Nadat je multisite networking hebt ingeschakeld, met s2Member framework en pro ingeschakeld, navigeer naar
s2Member → multisite (Configuraite)in het dashboard op je hoofdsite. -
Waar vind ik meer informatie?
-
- s2Member FAQs: http://s2member.com/faqs/
- Kennisbank: http://s2member.com/kb/
- Video tutorials: http://s2member.com/videos/
- Community: http://s2member.com/r/forum/
- Codex: http://s2member.com/codex/
-
s2Member vertalen
Beoordelingen
Bijdragers & ontwikkelaars
“s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions” is open source software. De volgende personen hebben bijgedragen aan deze plugin.
Bijdragers“s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions” is vertaald in 2 localen. Dank voor de vertalers voor hun bijdragen.
Interesse in ontwikkeling?
Bekijk de code, haal de SVN repository op, of abonneer je op het ontwikkellog via RSS.
Changelog
v260909
-
(Framework & Pro) Major Improvement: Until now, s2Member normally generated CSS/JS assets dynamically because some of their contents can change depending on the visitor or other conditions. Dynamic generation requires PHP and WordPress to load before each file can be built. s2Member can now build in advance the parts that don’t change and whose contents are shared across all visitors, and save them as static files, allowing the web server to return them directly without loading WordPress for each request. In our tests, static requests were consistently more than 100× faster than dynamic delivery, helping pages load faster while reducing server work. See WP Admin > s2Member > General Options > Performance & Caching > Static CSS/JS Optimization (beta).
- Flexible opt-in controls: Enable static CSS, static JavaScript, or both. The existing CSS/JS Lazy Loading option still controls which pages load s2Member’s files.
- Better caching for logged-in users: Most of s2Member’s JavaScript is the same for everyone, so it can now be shared and cached instead of being rebuilt separately for each visitor. Personal/member-specific values stay with the WordPress page and are never stored in reusable static files. This lets logged-in and logged-out visitors reuse the same shared JavaScript more effectively across page views.
- Pro and gateway support: Pro core and enabled-gateway CSS and JavaScript can use the same static delivery, combining, and minification options.
- Flexible static asset delivery: Static Framework and Pro assets can be kept separate for more granular caching, refreshing, and monitoring, or combined into one CSS file and one JavaScript file to minimize the number of requests.
- Optional automatic minification: Generated CSS and JavaScript can also be minified automatically. Smaller files take less time and bandwidth to download, helping pages load faster, especially on slower connections.
- Multilingual-site optimization: Sites that change language between pages or visitors can reuse the same static JavaScript file across languages. s2Member loads translated messages and other page-varying values with each WordPress page instead, while personal/member details always remain page-specific and are never stored in reusable static files. Single-language sites can keep more site-wide values in the static JavaScript file for maximum efficiency.
- Reliable automatic fallback: Static delivery is an optimization, not a requirement for the site to keep working. If a static file cannot be used, rebuilt, or delivered correctly, s2Member automatically falls back to a compatible dynamic delivery method instead of serving a stale or broken asset.
- Targeted refreshes and recovery: When relevant settings change, s2Member refreshes only the affected static files. During normal WordPress admin use, s2Member also checks that active generated files are still available and working. If a problem is confirmed, it can fall back safely, show an administrator warning, and provide a Refresh Static Assets control to recreate the files.
- Troubleshooting and event logging: When s2Member logging is enabled, a dedicated
css-js.logrecords important CSS/JavaScript delivery events such as generation and refreshes, configuration changes, loader or delivery problems, automatic fallbacks and recoveries, browser-reported runtime issues, and stale-file cleanup, without logging routine page loads. - Safer plugin updates: s2Member keeps its generated static JavaScript synchronized with the installed Framework and Pro versions. If an older generated file no longer matches the current plugin files, s2Member rebuilds it or falls back safely instead of risking broken JavaScript after an update.
- Cache-safe cleanup: Recently replaced static files are kept temporarily so visitors can still load pages cached with an older file URL. Older unused generations are cleaned up automatically, preventing the generated-assets directory from growing indefinitely.
-
(Framework & Pro) Improvement: Added a choice of loaders for dynamically generated CSS and JavaScript. The Lightweight s2Member Loader remains the default and avoids loading more of WordPress than necessary for better performance. A WordPress Loader option is also available, loading WordPress normally for these asset requests on sites where the server or security software blocks direct s2member-o.php requests. Configure it from WP Admin > s2Member > General Options > Performance & Caching > Dynamic CSS/JS Loader. See Mod Security (Odd 403, 503, 500 Errors)
-
(Framework & Pro) Fix: Due to an earlier change in WordPress, s2Member’s dynamic CSS and JavaScript loader could end up loading more of WordPress than necessary, making those files slower to load. Its original lightweight loading behavior has now been restored. See: s2Member-Only Mode
-
(Framework) Improvement: Added a shared checkout recovery system that lets supported gateways preserve an in-progress checkout across requests, prevent overlapping processing, and recognize a checkout that already completed even if the browser lost the final response. Recovery information can be retained securely for up to 7 days by default, providing a common foundation for safer retry and recovery behavior across payment gateways.
-
(Pro) Improvement: PayPal Checkout Pro-Forms now keep a durable checkout identity across reloads, back/forward navigation, and interrupted browser requests. This gives s2Member a reliable way to reconnect the customer with the same PayPal checkout already in progress, while remaining compatible with older in-progress recovery state during the transition.
-
(Pro) Security: Hardened password handling across Pro-Forms as part of the new checkout recovery protections. Submitted passwords are not carried into reusable PayPal Checkout recovery state or repopulated if the form has to be shown again after submission. If an interrupted checkout is later recovered without the original browser session, WordPress’s secure set-password flow is used instead.
-
(Pro) Security: Hardened Specific Post/Page checkout recovery by minimizing the form data saved for interrupted-checkout recovery. Sensitive payment fields are explicitly excluded from saved recovery state, adding an extra safeguard against unexpected checkout data being retained.
-
(Pro) Fix: Significantly extended Stripe Pro-Form duplicate-billing protection for interrupted or retried checkouts. If a reload, interrupted request, lost response, or 3D Secure retry leaves an existing Stripe payment or subscription in progress, s2Member now preserves enough checkout state to find and resume that same payment or subscription instead of accidentally starting another one. This extends the duplicate-charge protection added in v260829 to several additional failure and recovery paths. See thread 13589.
-
(Pro) Fix: Improved handling when a successful Stripe Pro-Form checkout completes on the server but the final confirmation never reaches the customer. Because the form can still appear unfinished, the customer may submit it again even though Stripe already completed the payment. Successful checkout results are now retained server-side so s2Member can recognize the completed checkout and resume from the saved result instead of treating the retry as a new payment attempt.
-
(Pro) Fix: Strengthened duplicate-subscription protection in PayPal Checkout Pro-Forms. Subscriptions are now created server-side and recorded before browser approval continues, so reloads, lost PayPal responses, interrupted callbacks, and retries can recover and reuse the subscription already created at PayPal instead of creating another one.
-
(Pro) Fix: Corrected PayPal Checkout subscription activation handling so membership access is not granted while PayPal still considers the subscription pending approval. s2Member now waits for PayPal to confirm activation, and can recover that confirmation through PayPal’s webhook if the browser response is lost or delayed.
-
(Pro) Fix: Added comprehensive recovery for interrupted or delayed PayPal Checkout one-time payments. s2Member now keeps track of both the PayPal order and its payment capture, safely handles lost or ambiguous responses, keeps access pending until PayPal confirms the payment completed, and can later recover a completed payment through either the browser or PayPal’s webhook without attempting a second capture. The recovery state is also kept deliberately minimal without retaining sensitive checkout data.
-
(Framework) Performance: Reduced overhead in high-frequency query and capability checks by bypassing hook and filter setup when nothing is registered and avoiding unnecessary construction of hook context variables, while preserving registered callbacks and WordPress
allhook compatibility. Screens and operations that perform many capability checks, such as the WordPress Users list, can benefit especially from these savings. -
(Framework) Performance: Reduced database overhead during page loads by eliminating repeated access-restriction database queries within the same request, reusing the initial lookup result.
-
(Pro) Improvement: The Pro updater now handles version mismatches more clearly when the latest Pro release is ahead of the installed Framework. It recommends updating the Framework first, or links to the Release Archive for a matching Pro version when staying on the current Framework.
-
(Pro) Performance: Moved checks for available Pro updates to a background task. The latest available Pro version is now saved locally and reused for up to a day when deciding whether to show the Pro Updater. This way, slow Pro availability checks or connection problems can’t delay frontend or admin page loads. After Framework updates, a fresh background check keeps compatibility information current.
-
(Pro) Performance: Moved the Pro server environment details collection to a background task, so it can’t delay normal admin page loads.
-
(Pro) Performance: Eliminated repeated cron and transient housekeeping during normal page loads when End-of-Term reminders are disabled, moving the necessary cleanup to settings changes and stale background callbacks.
-
(Framework) Improvement: End-of-Term Administrative Notes in the user’s profile now use the level custom names when the “Force WordPress to use your Labels” setting is enabled. Also, if a user is already in the configured demotion role, the note now says so instead of recording a “role change” to the same role.
-
(Framework) Fix: Solved a remaining PayPal cancellation EOT issue when stored IPN Signup Vars are completely missing. An older subscription check could prevent the newer PayPal lookup from running, causing the EOT to fall back to an incorrect one-day period. s2Member now uses PayPal’s next billing date when available. Thanks to Felix for reporting this. See thread 13462.
-
(Framework) Fix: Improved Automatic End-of-Term health warnings on low-traffic sites. A delayed WP-Cron event, which can happen when there have been few or no site visitors to trigger it, is now shown as an Attention item without triggering the admin warning by itself, while missing cron or an actual overdue EOT backlog still triggers the stronger warning. EOT warning links also now open the relevant settings panel and jump directly to the affected setting.
-
(Framework) Fix: Prevented PHP warnings during some Stripe cancellation/End-of-Term processing when currency information is missing. s2Member now recovers the stored payment currency when possible, and continues processing cleanly without PHP warnings.
-
(Framework) Fix: In some edge cases, legacy encryption/decryption could trigger a PHP 8.5 deprecation warning for certain byte values. The byte handling is now explicitly normalized while preserving compatibility with existing encrypted data.
-
(Framework) Fix: Redacting sensitive data in large multiline gateway/API logs could cause the regular-expression redaction step to fail and trigger PHP 8.1+ deprecation warnings. Redaction now handles large log entries more reliably.
-
(Framework) Fix: The bundled Mailchimp API client could trigger a PHP 8.1+ deprecation warning by passing a deprecated
nullvalue during query-string construction. It now uses the correct empty-string value instead, preserving the same API request behavior. -
(Pro) Fix: ClickBank request processing could trigger PHP 8.1+ deprecation warnings by passing a deprecated
nullvalue during query-string construction. Those calls now use the correct empty-string value instead, preserving the same request behavior. -
(Framework) Fix: PayPal notifications and returns could trigger PHP warnings when the optional
s2member_paypal_proxyands2member_paypal_proxy_usefields were absent. Those optional fields are now set to empty values when missing before processing, while preserving existing gateway integration behavior. -
(Pro) Fix: Prevented a PHP warning when processing malformed Stripe webhook payloads by validating the decoded event before accessing its ID.
-
(Framework) Fix: Corrected an off-by-one issue in Brute Force Login Protection that allowed one additional login attempt after the configured failed-login limit had been reached.
v260829
-
(Framework) Major Improvement: Rebuilt the Automatic End-of-Term processing engine so membership expirations are handled more reliably and promptly when due, even on busy sites or after delays, while making the system safer to administer and easier to review and troubleshoot.
- Faster, adaptive processing: Instead of stopping after 6 users, the new engine uses the safe processing time available in each run and adapts to current speed, allowing it to handle hundreds of users in one pass.
- Rapid queue catch-up: s2Member processes each member as promptly as practical after their actual EOT time is reached. If work remains, it continues about a minute later instead of waiting for the next regular 10-minute check. In our stress testing, a 1,000-user queue was processed in under 2 minutes, while the old 6-user limit would take almost 28 hours.
- More resilient processing: Overlapping runs are prevented, interrupted or stale runs recover cleanly, and unfinished work remains available for the next pass instead of being lost or unnecessarily delayed.
- Safer “Delete” behavior and review: Automatic Delete now removes membership access and moves the user account to Pending Deletion instead of permanently deleting it, preserving useful payment/subscription details for review before single/bulk deletion. Irreversible automatic deletion can still be enabled with the
ws_plugin__s2member_allow_eot_user_deletionfilter. WP Admin > Users > Pending Deletion - New End-of-Term user lists: Added separate Current and Previous lists with EOT Time, Last EOT, and EOT Demotion columns. Current shows users with an EOT, earliest first; Previous shows prior EOTs, most recent demotion first. Older demotion times are recovered from Administrative Notes where possible. WP Admin > Users > End-of-Term Current / End-of-Term Previous
- Better demotion history: EOT actions, including moves to Pending Deletion, now leave more useful Administrative Notes with the role change, removed Custom Capabilities, subscription details, and the EOT that triggered the action. For example: 2026-08-31 00:03 EDT s2Member: Demoted from Level 1 to Subscriber (removed ccaps: courses). PayPal I-ABC123. EOT 2026-08-31 00:01 EDT.
- Visible health and automatic recovery: A new Automatic Behavior Status shows pending and overdue EOTs, recent processing activity, the next scheduled run, and the current processing runtime, making delays and other problems visible instead of silent. s2Member repairs a missing WP-Cron schedule automatically when possible, and alerts administrators when a problem persists and needs attention.
-
(Pro) Major Improvement: Rebuilt the End-of-Term Reminder Email processing engine so renewal notices have a better chance of going out promptly on their intended day, even after WP-Cron delays or temporary email sending problems that could previously prevent them from being sent.
- Fast, adaptive processing: The new engine replaces the old 6-member limit with safe runtime-based processing, prevents overlapping runs, recovers interrupted ones, and continues about a minute later when more work remains. On our test server, 1,000 reminders were handed off through WordPress’s mail system in about 42 minutes, while the old engine would need almost 28 hours.
- Independent reminder engine: Reminders based on stored End-of-Term dates now have their own schedule and processing engine, so they no longer depend on membership-expiration processing completing first and aren’t held up by a large or stalled End-of-Term queue.
- Forgiving timing and smart retries: Reminder eligibility now uses calendar days, giving s2Member opportunities throughout the intended send day plus an extra recovery day in case of delays. Failed sends are retried after about 10 minutes, 30 minutes, 1 hour, and then every 3 hours while still eligible, with each recipient tracked independently to avoid duplicate resends.
- Visible health and automatic recovery: A new End-of-Term Reminder Status shows scheduling activity, recent successful delivery, and recipients currently being retried, with additional failure and recovery details when something goes wrong. s2Member repairs a missing reminder schedule when possible, retries failed recipients automatically, and alerts administrators when problems persist and need attention.
-
(Framework & Pro) Fix: Fixed the long-standing issue where the Automatic End-of-Term setting could appear blank when its WP-Cron event was missing. The saved setting now remains visible while s2Member reports and repairs the scheduling problem separately.
-
(Pro) Fix: End-of-Term renewal reminders are no longer sent when membership access ended because of a refund, payment reversal, or chargeback. These payment exceptions are now distinguished from normal membership expirations so they don’t trigger inappropriate renewal notices.
-
(Pro) Enhancement: Modernized s2Member Pro-Forms with PayPal Checkout, using PayPal’s current REST APIs and Smart Payment Buttons for off-site payments. When PayPal Checkout is enabled in s2Member, it replaces the legacy PayPal Express Checkout integration for payments completed on PayPal’s site. Existing Pro-Form shortcodes work as-is (no edits required). Enable it under WP Admin > s2Member > PayPal Options > PayPal Checkout (Beta).
-
(Framework) Improvement: Strengthened PayPal Checkout REST order validation, capture reliability, retry handling, and payment processing safeguards.
-
(Framework) Improvement: Better PayPal Checkout button feedback with clearer, more visible error and status messages below the button.
-
(Framework) Improvement: Better compatibility for sites using PayPal Checkout while older PayPal subscriptions remain active. Since PayPal subscriptions generally need the integration that created them, s2Member now uses the appropriate one for next payment dates, reminder emails,
[s2EOT], and cancellations. -
(Framework) Security: Strengthened PayPal Checkout return validation and payment-flow integrity.
-
(Framework) Fix: Improved PayPal Checkout subscription fulfillment retry handling, preventing failed payment notifications from being incorrectly marked complete and allowing browser or webhook recovery to retry safely.
-
(Framework) Fix: PayPal Checkout now registers all required webhook events. Existing configured webhooks are updated automatically after upgrading, adding notifications for subscription activation/updates, payment refunds/reversals, and disputes/chargebacks.
-
(Pro) Fix: Strengthened Stripe Pro-Forms against duplicate charges from concurrent or repeated submissions of the same rendered checkout. Stripe requests now use a stable per-checkout idempotency ID, simultaneous submissions are blocked while payment processing is in progress, and a failed update to an existing PaymentIntent no longer falls through to creating another one. Thanks to DrCheap for the detailed report and investigation. See thread 13589.
-
(Pro) Fix: Fixed a Stripe compatibility issue that could cause
[s2Member-Profile /]and Stripe billing-update forms to crash when retrieving an existing subscription with newer Stripe API responses/SDK behavior. Thanks to Tim Hibberd for reporting it and providing a patch. See thread 13575. -
(Pro) UI: Updated Stripe Webhook/IPN setup guidance to list all seven events s2Member handles. Sites with an existing Stripe webhook configured for selected events should make sure all seven are selected, including
charge.dispute.created, so disputes/chargebacks can follow the configured Reversals/Disputes EOT behavior. -
(Pro) Improvement: Added an optional
placeholderattribute for Authorize.Net, PayPal, and Stripe Pro-Form Checkout Options. This allows a Pro-Form to start with a non-payable prompt instead of automatically selecting the first Checkout Option, requiring the customer to choose a real option before the full checkout form is shown. -
(Framework & Pro) Fix: Improved shortcode attribute handling when editors replace straight quotes with smart/curly quotes. s2Member now also normalizes literal smart quotes so values such as
attribute=“0”are interpreted correctly. Thanks to Vincent for reporting it. See thread 13572. -
(Framework) Enhancement: Added a hook after profile modifications are saved and s2Member refreshes the user data, allowing integrations to read freshly updated user and custom profile fields. Thanks to Craig for bringing attention to this use case. See thread 13515.
-
(Framework & Pro) Improvement: Bumped PHP version compatibility up to PHP 8.5.9 after addressing the remaining deprecation notices and related compatibility issues, while maintaining support for older PHP versions.
-
(Framework) Fix: Hardened PayPal recurring-payment handling for missing optional IPN fields and memberships without Custom Capabilities, preventing PHP warnings and deprecation notices.
-
(Framework) Fix: Hardened gateway notification and return handlers against missing or null optional transaction fields, preventing PHP warnings and deprecation notices.
-
(Framework) Fix: Prevented PHP warnings during registrations or membership updates when optional details (like Custom Capabilities or EOT) weren’t used.
-
(Framework) Fix: Corrected an edge case in subscription modifications where an optional EOT component could end up in the Custom Capabilities value.
-
(Framework) Fix: Fixed PHP 8 compatibility issues in legacy OpenSSL/RSA signing and the Markdown fallback that could fail in some cases.
v260814
-
(Framework) Improvement: Better s2Member Security Encryption Key handling and related guidance in the admin panel.
-
(Framework) Improvement: Hardened input validation and sanitization for the
s2Key,s2File,s2Stream, ands2Member-PayPal-Buttonshortcodes. -
(Framework & Pro) Improvement: Renamed and expanded the
s2Getshortcode’s user-field whitelist into the shared Shortcode User Fields Whitelist setting, now used fors2Get’suser_idattribute ands2Member-List’sshow_fieldsattribute. Administrators are warned when either shortcode attempts to display an un-whitelisted field’s value that doesn’t belong to the current user viewing the page. -
(Framework & Pro) Security: Improved validation and hardened handling of serialized data throughout s2Member.
-
(Pro) Improvement: Hardened input validation and sanitization for the
s2Member-Login,s2Member-Summary,s2Member-Gift-Codes,s2Member-List,s2Member-List-Search-Box, ands2Member-Pro-ClickBank-Buttonshortcodes, as well as the Pro Login Widget. -
(Pro) Security: Added stricter handling for
s2Member-List’sshow_fieldsattribute. s2Member will warn administrators about detected fields that still need review. Fields not whitelisted will not be displayed. Sites usingshow_fieldsshould review General Options > Shortcode User Fields Whitelist and allow the fields their Member Lists are intended to display. -
(Pro) Security: Added safer handling and a whitelist for the
templateshortcode attribute, used by thes2Member-List,s2Member-List-Search-Box, and Stripe, PayPal, and Authorize.Net Pro-Forms shortcodes. s2Member will warn administrators about detected templates that still need review. Templates not whitelisted will not be used, and the standard template will be used instead. Sites using custom templates should review General Options > Pro Shortcode Templates Whitelist and allow their custom template files. -
(Pro) Fix: Prevented the Pro updater from offering or installing a Pro release newer than the installed s2Member Framework, avoiding compatibility issues until the Framework is updated first.
-
(Pro) Fix: Prevented Stripe payment processing from continuing after Pro-Form validation rejects a submission, avoiding misleading Stripe card-field errors when other required form fields are missing.
-
(Pro) Fix: Updated Stripe Pro-Forms to use the shortcode’s
validate_zipcodeattribute correctly, so it can override the default setting to collect and validate the card’s postal code.
v260805
-
(Framework) Improvement: Replaced TinyURL-based shortening for generated Registration Access and Specific Post/Page Access URLs with new built-in s2Member short links, stored temporarily with WordPress transients. Existing TinyURL settings now use the built-in shortener automatically, avoiding TinyURL’s deprecated no-key API endpoint and extra third-party pages shown before the destination.
-
(Framework) Improvement: Better PayPal Checkout cancellation button handling when stored IPN Signup Vars are missing. s2Member now checks PayPal subscription details via API before cancellation, uses PayPal’s next billing time plus the configured EOT grace period for the EOT time, and falls back to PayPal’s subscription management page when a safe local cancellation cannot be completed. See thread 13462.
-
(Framework) Security: Hardened the
[s2Stream]shortcode against executable JavaScript injection by users with post-editing privileges. Attributes used to configure JW Player are sanitized and validated more strictly, and customplayer_pathvalues must now be explicitly whitelisted using thews_plugin__s2member_sc_get_stream_player_pathsfilter. -
(Framework) Security: Improved sanitization of sensitive data in s2Member debug logs.
-
(Framework) Fix: Prevented a PHP 8+ fatal error during PayPal Standard PDT/IPN return handling when PayPal reports an invalid or unexpected charset. PayPal return data is now converted to UTF-8 defensively, with fallback handling when the reported charset is not accepted by
mb_convert_encoding(). -
(Pro) Improvement: Added safer handling for rare Stripe Pro-Form subscription checkouts where the first payment or setup confirmation remains pending. s2Member now delays paid-access changes until Stripe confirms the subscription is ready, helping avoid premature access while reducing the chance of confirmed Stripe subscriptions not matching s2Member access.
-
(Pro) Fix: Fixed validation of zero-like trial period values such as
tp="0.00", so they are treated the same astp="0"instead of being rejected as an invalid trial period.
v260508
-
(Framework) Fix: PayPal Checkout cancellation shortcodes now keep
output="anchor"clickable for logged-out visitors. Onlyoutput="button"requires the member to be logged in. See thread 13450 -
(Framework) Fix: PayPal Checkout no longer aborts if the customer’s IP address changes during checkout. IP mismatches are logged, but valid checkouts continue processing.
-
(Framework) Fix: Prevent false Auto-EOT demotions when a stored Auto-EOT time is
0, and improve logging for invalid Auto-EOT values. See thread 13412 -
(Framework) Fix: Prevented a PHP 8.1+ deprecation notice while reading registration times when the stored value is missing or false.
-
(Framework) Improvement: Improved PayPal Checkout button loading with a client-side fallback when the PayPal SDK is missing from the final page output.
-
(Pro) Fix: Prevented deprecation notices on newer PHP versions, which could interfere with automatic login/redirects after Stripe checkout.
-
(Pro) UI: Improved cancellation pro-form submit button text. Cancellation forms now say “Cancel Subscription” instead of the generic “Submit Form”. See thread 13438
v260410
-
(Framework) Fix: Reduced the upfront requirements for processing PayPal Standard
subscr_cancelIPNs so valid cancellations are not ignored when supporting values are missing, stale, or non-membership-specific. -
(Framework) Fix: Prevent incorrect s2Member notifications in some PayPal Checkout cases where several webhooks are received about the same subscription.
-
(Framework) Fix: Prevent duplicate processing and notifications when PayPal sends both a webhook and an IPN for the same PayPal Checkout subscription payment.
-
(Framework) Fix: Added subscription modification cancellation support to the Framework, which was previously only available in the Pro addon.
-
(Pro) Fix: Made subscription modification cancellation gateway-aware, preventing orphaned active subscriptions when a member starts a replacement subscription through a different gateway.
-
(Pro) Fix: Prevented rare cases where subscription modification processing could cancel the newly created subscription by mistake.
-
(Pro) Fix: Improved Stripe customer lookup during checkout retries by falling back to email when the stored Stripe customer ID is missing, stale, or no longer retrievable.
v260325
-
(Framework) Fix: Improved PayPal Checkout webhook idempotency to prevent duplicate processing during repeated/concurrent webhooks, while preserving normal behavior.
-
(Framework) Fix: Resolved a PayPal IPN issue where some
subscr_cancelnotifications were ignored because the cancellation handler failed before it had fully identified the recurring subscription. -
(Framework) Improvement: Added IPN Signup Var lookups for missing PayPal cancellation IPN values like
period1,period3,item_number,item_name, andpayer_email, preventing validsubscr_cancelnotifications from being ignored. -
(Framework) Improvement: Moved s2Member’s translation files to
/languages, following the WordPress standard, and updated.moloading to support that directory while continuing to support the standard and legacy WordPress locations. -
(Framework) Improvement: Hardened PayPal Standard IPN endpoint response handling and added debug logging for hosts/security layers that incorrectly return HTTP 403 after successful processing.
-
(Framework) Enhancement: Added
ukpostcodeas an expected-value option for Custom Registration/Profile Fields, with matching server-side and client-side validation for UK postcode input. The validation is designed to be reasonably broad, including standard UK formats and related special cases. Thanks to Gerard Earley for contributing the patch. See thread 12200 -
(Framework) Enhancement: Added a new General Options > s2Get Shortcode setting to allow
user_idfor whitelisted user fields, defaulting to current-user. Also updated the s2Get KB article accordingly. -
(Pro) Fix: Updated Stripe card charge and PaymentIntent requests to use
statement_descriptor_suffixinstead ofstatement_descriptor, fixing card-payment errors where Stripe no longer acceptsstatement_descriptorfor card payments. -
(Pro) Fix: Corrected Stripe subscription checkout so resumed PaymentIntent flows no longer go through the wrong intent-status handler.
-
(Pro) Fix: Stripe now stops cleanly after card declines, instead of continuing into secondary intent/payment-method errors.
-
(Pro) Fix: Improved Stripe recurring-payment setup to better support future-charge authorization requirements, fixing failures in countries with stricter payment rules, including India.
-
(Pro) Fix: Stripe now updates recurring default payment methods only after a successful intent result, instead of earlier in checkout.
-
(Pro) Fix: Billing-update SetupIntent creation failures in Stripe now return the proper error response.
-
(Pro) Fix: Prevent duplicate/retried Stripe webhook events from being processed more than once, including near-simultaneous retries of the same Stripe event ID
-
(Pro) Fix: prevent Stripe billing modification/replacement from triggering EOT behavior for the cancelled old subscription while s2Member is still updating the member account with the new subscription.
-
(Pro) Fix: Removed a trailing-comma syntax issue in Stripe subscription update code that could cause PHP compatibility errors on older supported PHP versions.
-
(Pro) Fix: s2Member now cleans up incomplete subscriptions left behind by failed 3D Secure authentication attempts during Stripe checkout, and gives the customer a more clear payment failure message.
-
(Pro) Improvement: Added dedicated s2 Stripe log entries for non-fatal failures while updating the default payment method after successful intent completion.
v260312
-
(Framework) Fix: Prevent a PHP 8.1+ deprecation notice from appearing above the admin Users table in some cases.
-
(Framework) Security: Improved debug log sanitization.
-
(Framework) Improvement: PayPal Checkout credential test and OAuth failure log entries now include client_len_hash / secret_len_hash values (length_hash, e.g. 80_4d9a7c1b2e8f4a21) to help compare attempted credentials during troubleshooting without exposing raw values.
-
(Framework) Enhancement: Added a new No-Cache Headers Behavior option under General Options > Performance & Caching, making no-cache behavior configurable from the admin UI. It includes:
Alwaysmode, the legacy safe default that prevents caching site-wide in case user-conditional output appears.Selectivemode, which was previously available only through a filter and may improve caching for guests, but can miss some runtime no-cache triggers.- The new
Evaluativebeta mode, which evaluates the page with more runtime information and may allow more pages to be cached safely for guests. - An optional debug header to help troubleshoot no-cache behavior.
-
(Framework) UI: Clarified the Download Options text to explain that unique download limits are counted in the last X days (rolling window), reducing confusion about whether the limit resets on fixed calendar dates.
-
(Framework) UI: Improved the PayPal Checkout credentials test failure message.
-
(Framework) UI: Fixed the PayPal button encryption admin notice so that it shows only to administrators in the WP Admin area, not non-admin users.
v260301
-
(Framework) Bug Fix: Fixed mismatched
<label for="">and<input id="">attributes for checkbox/radio options in Custom Registration/Profile Fields; this also restores proper client-side validation for required checkbox/radio groups. -
(Framework) Fix: Hardened the Edit User Profile screen on PHP 8+ to avoid errors if a user’s Auto-EOT time is stored as a date string (e.g. YYYY-MM-DD) rather than a Unix timestamp (as can happen after imports/migrations).
-
(Framework) Fix: Fixed …
