- This release is all about security and bug fixes, with very few feature additions.
- Bug fix, %%registration_url%% in the Signup Confirmation Email was being replaced with 1, instead of the full URL. This bug was first introduced in s2Member v2.8.7. This has been corrected in v2.9.
- s2Member now uses MCRYPT_RIJNDAEL_256 / CBC through mcrypt_encrypt() when it's available on your server. XOR encryption is used as a fallback for hosts that do not have the mcrypt extension installed. The MCRYPT_RIJNDAEL_256 algorithm provides much better security.
- A full security review of s2Member has been completed, in anticipation of the s2Member Pro Module; being released later this month ( May 2010 ). A new panel under: s2Member -> General Options -> Security Encryption Key should be configured. Just click the auto-generate button there. s2Member will assign a special Security Key to your installation.
- Please report all bugs. If you have any trouble with this release, you can always revert back to a previous version until the issue is corrected.
[ download the latest version of s2Member here ]