Skip to main content

Changelog

Follow new updates and improvements to SnipVault.

SnipVault 1.3.3

SnipVault 1.3.3 is out now.

This one's a mix of quality-of-life improvements and some important bug fixes.

Rename tags in place. You can now rename tags directly from the snippet editor tag picker. Hit the edit icon, type the new name, and it updates across every snippet that uses that tag. No more deleting and re-tagging.

Smarter PHP collision checks. If you've ever had a snippet blocked because a class method happened to share a name with a WordPress core function — like get_categories() on an Elementor widget — that's fixed. The collision checker now uses token-based analysis so it only flags unguarded global function calls. And if you know what you're doing, there's a per-snippet "Allow existing functions" toggle to skip the check entirely.

Hook autocomplete. The "Load on hook" field is now a proper autocomplete. Start typing, arrow through the suggestions, hit Enter. Works with custom hook names too.

Template picker. If you've got more than one template, "New from template" now opens a modal where you can search and pick the one you want instead of just grabbing the first match.

Other improvements:

  • The PHP error log panel is now resizable by dragging its edge, and it remembers your width between visits.

  • Panel resize handles are easier to grab — the drag bar shows up when you're near the edge, not just on a pixel-thin strip.

  • Folder rename now requires a double-click, so single-clicking a folder just opens or closes it like you'd expect.

  • Notifications replaced with Vue Sonner for cleaner, top-center toasts.

Bug fixes:

  • Fixed the snippets list crashing with a Cannot read properties of null error when snippet settings included extra keys.

  • Fixed revision timestamps showing UTC instead of your WordPress timezone.

  • Fixed "New from template," duplicate, and import failing with a rest_invalid_param: comment_status error.

Update from your WordPress dashboard or grab it from the site.

SnipVault 1.3.2 — Snippet Functions: Turn Any Snippet Into a Live Webhook Endpoint

Your WordPress snippets just learned to answer the phone.

SnipVault 1.3.2 introduces Snippet Functions — a way to expose any published PHP snippet as a signed, authenticated HTTP endpoint on your site. That means your snippets aren't just code that runs on page load anymore. They can receive incoming webhooks from Stripe, GitHub, Zapier, n8n, or anything else that can fire an HTTP request.

This is, as far as we know, a first for the WordPress snippet manager category. No other snippet plugin lets you go from "I wrote a PHP snippet" to "it's a live, secured API endpoint" in a single toggle.


How Snippet Functions Work

Publish a snippet, flip it to a Function, and it's immediately reachable at a clean URL:

https://yoursite.com/sv/your-slug

Or via the REST API fallback at /snipvault/v1/functions/{slug}/invoke.

Every function comes with the infrastructure you'd expect from a proper webhook receiver:

  • Secret-header authentication — callers must include your secret in the request headers. No secret, no execution.

  • Rate limiting — built in at the endpoint level so a misconfigured sender can't hammer your site.

  • Invocation logs — the last 50 calls are stored with status, timing, and payload data, visible right from the dashboard.

  • Admin replay — re-fire any successful or test invocation with one click to debug or re-process.

  • Dashboard telemetry — see call volume, success/failure rates, and response times at a glance.

The security model is intentionally tight. Replay is restricted to successful and test invocations only — failed auth bodies aren't stored. GitHub imports can't silently enable a function or plant a secret. Capability-based auth is POST-only. Rate limits apply after authentication, not before. And settings saves are validated to prevent weak secrets.

Snippet Engineer Can Build Them Too

The AI-powered Snippet Engineer now has two new tools: expose_as_function and test_function, along with a built-in webhook recipe. That means you can describe what you need — "create a webhook that receives a Stripe payment event and logs the customer email" — and the agent will author the snippet, write fixture tests, and deploy the endpoint. All without leaving the SnipVault interface.


Everything Else in 1.3.2

GitHub Sync reliability overhaul. OAuth tokens that expired after ~8 hours are now refreshed automatically before API calls, with a single retry on 401. Tokens have also been moved to their own dedicated option key, so saving unrelated settings can no longer accidentally wipe your GitHub connection. And the GitHub Library no longer 404s when your configured base path doesn't exist yet — it returns an empty list gracefully instead.

Portable snippet storage. Snippet file paths are now stored as uploads-relative paths (snipvault/slug_123.php) instead of absolute filesystem paths. Migrate hosts, change server configs, move your uploads directory — your snippets keep working. Existing absolute paths are remapped at runtime and rewritten on the next upgrade.

UI fix for project cards. Cards no longer render with dark-only colors when you're in light mode. They now share the same surface, text, and footer treatments as automation cards across both themes.


Update Now

SnipVault 1.3.2 is available now. Update from your WordPress dashboard or download from your account.

If you've been duct-taping together webhook receivers with custom plugins or functions.php hacks — this one's for you.

SnipVault 1.3.1

A focused bugfix release cleaning up the rough edges from the Projects rollout in 1.3, plus a few UI polish items.

🐛 Fixed: Projects & Imports

The biggest fixes here are around project assignment on import — a few different paths were writing snippets to disk without properly linking them into your project-scoped list:

  • GitHub Library imports weren't assigning a project — imported snippets (including drafts) existed on disk but wouldn't show up in your project's snippet list. Imports now use your active project (or Default), and re-importing the same GitHub path updates the existing snippet instead of creating a duplicate.

  • Cloud Library and JSON file imports were landing in Default instead of whatever project you had selected. Fixed.

  • Added snippet_project to the GitHub .snipvault.json sidecar metadata so same-site sync can correctly restore project assignment.

  • Fixed the agent's import_from_library tool sending a single path instead of the required paths array — imports now also pass status and project_id correctly.

  • Ran a migration (projects v2) to backfill any snippets/folders that were missing valid project meta, moving them to Default.

🎨 UI & Polish

  • Monaco editor's dark theme now uses zinc-900 (#18181b) to match the rest of the app's dark palette — no more mismatched editor background.

  • Redesigned the settings page with a grouped card layout — clearer section hierarchy, more breathing room, readable text-sm descriptions throughout.

  • Fixed layout issues on the snippet settings and PHP error log screens.

  • Added ThinkingOrb canvas animations for agent working/thinking states — the header status and inline loading indicator now map activity labels to orbit, globe, wave, or ribbon modes depending on what the agent's doing.

🔐 Licence Key Storage

Licence keys now live in their own dedicated snipvault_license option instead of being bundled into snipvault_settings. Activation and removal go through new snipvault/v1/license/* endpoints, so an unrelated settings save can no longer wipe your key. Existing keys migrate automatically — no action needed.

⚡ Performance

  • Fixed an intermittent critical error when opening the PHP Error Log — large log files no longer load fully into memory (now a tail-capped read), path resolution falls back to wp-content/debug.log, source lookups are cached, and the dashboard now uses a single error-log request instead of two parallel full parses.

Also Fixed

  • Frontend live reload script 404 on some installs — the script is now copied into app/dist during the Vite build and enqueued from there instead of app/src.

Earlier updates