Release notes / MediaShield Pro
Premium Plugin Plugin

MediaShield Pro

A watermark proves who leaked your video after the fact. MediaShield Pro stops the copy: ClearKey DRM encryption, playback heatmaps, realtime viewers, LMS auto-complete, an email-capture gate, and CSV and PDF export. Encrypt the file, then read the numbers.

4 releases
v1.3.0 latest
August 31, 2026 shipped

v1.3.0 Latest

August 31, 2026
New 1 Improve 9 Fix 8 Security 2 Dev 8 Compat 1

New

  • DRM can be turned on. Encrypted playback is an experimental preview: it appears as a protection level on a video only after you have chosen a packaging method, so a site that has not set one up cannot pick a level that would not protect anything.

Improve

  • CSV exports of watch sessions and milestones are no longer capped. They previously stopped at 50,000 rows without saying so, which could hand someone an incomplete file believing it was whole.
  • A user export that does hit its limit now says so in the file itself.
  • CSV exports use less memory on large datasets. They loaded the whole result set before writing, despite describing themselves as streaming.
  • Retired the [mediashield_upload] front-end shortcode. It never worked - five separate faults, including a required field with no selectable option that made the form impossible to submit on any site without a connected platform. Upload videos from Videos > Add New instead.
  • Removed the email gate. It could never run on a default install: WordPress-gated videos deny logged-out visitors before the gate is reached, and on a members-only site the viewer is already identified, so the gate captured nothing the site did not already have.
  • The "Require enrollment" setting now works as a master switch. It saved and was read by nothing, so turning it off did not open access and turning it on did not gate anything.
  • Uploads now go to the destination set in Default Upload Target. The setting saved and every upload ignored it.
  • Changing the default protection level now applies to videos you already have. Import and upload saved a copy of the default onto each video, which then outranked the setting forever.
  • Removed the DRM packaging options that never did anything. "Local - Shaka Packager" and "AWS MediaConvert" appeared in the DRM Method list, and the Shaka Packager Path field and Auto-package toggle appeared below it, but no video was ever packaged by any of them. If your site had one of those methods selected, DRM Method now reads None, which is what it effectively was.

Fix

  • A DRM-protected video now reaches the encrypted player. It was handed no playback address, so the encrypted player never started and the video played through the standard player unencrypted instead. Needs MediaShield 1.3.0.
  • Revoking a viewer's DRM access now denies them a new license. Revocation was recorded and reported back to you, but the next license request minted a fresh one and handed over the content key, so revoking changed nothing.
  • Videos uploaded to a connected platform now play. The video's address was saved as the temporary file path of the upload on your server for Vimeo, YouTube and Wistia, and as a playlist address Bunny refuses to serve unsigned for Bunny Stream, so an uploaded video never played on any of the four.
  • Videos imported from Bunny Stream now play. Import saved the video's playlist address rather than its player address, and Bunny refuses unsigned playlist requests, so every imported video showed "403 Forbidden" in the player and none of them had ever played. Videos imported before this update are corrected automatically when you update.
  • Connected platforms work again. Bunny Stream, Vimeo, YouTube and Wistia credentials were saved in one format and read back in another, so every connection reported itself as connected while no request using it could succeed.
  • The plugin no longer fails to load from a fresh clone, which took the whole site down with it.
  • Fresh installs now create the DRM licenses table. An inline comment inside the table definition made the statement fail silently, so new sites got every other table except this one and DRM license issuance could not work. Existing sites were unaffected.
  • Deleting a video no longer deletes the original from Bunny, Vimeo, YouTube or Wistia. It is left in place so you can add it back whenever you want.

Security

  • VPN detection no longer sends visitor IP addresses over an unencrypted connection. It now uses HTTPS and requires an API key, and stays off until one is entered.
  • Shaka Packager is now run without a shell. The previous call was correctly escaped and not a vulnerability, but malware scanners match on the shape of the call, so customers could see their site flagged as compromised.

Dev

  • Added the ms_vpn_api_key setting, with a field on the Alerts screen. The settings response reports only whether a key is set, never the key.
  • Pro registers its DRM protection level through the new mediashield_protection_levels filter in MediaShield 1.3.0.
  • Plugin::is_licensed() delegates to Licensing\License::is_valid(). The old inline check compared an array against the object the licensing SDK stores, so it could never return true.
  • [mediashield_upload] stays registered as a stub that renders nothing for visitors. Deleting the handler would have printed the raw shortcode text on any page still carrying it.
  • Removed the ms_email_captures table, the /email-gate/submit and /email-gate/test-webhook REST routes, the mediashield_pro_email_captured action, and the five ms_email_gate_* / ms_email_retention_months options.
  • Collected email-gate leads are deleted on upgrade. Export them before updating if you still need them.
  • Pro's test suite runs for the first time. It was pinned to a PHPUnit version the WordPress test suite cannot use, so every test failed before running.
  • Deleted DRM\Packager and KeyServer::generate_key(). Packager had no callers anywhere in either plugin and generate_key() was called only from inside it, so ms_drm_keys could never be written. The mediashield_before_drm_package and mediashield_after_drm_package actions and the mediashield_pro_drm_package job are gone with it. KeyServer::get_key() and WidevineLicense remain - DRMController calls them.

Compat

  • Requires MediaShield (free) 1.3.0. Install both updates together.

v1.2.0

July 24, 2026
Improve 1 Fix 1 Dev 2 Compat 1

Improve

  • Removed the email gate. It could never run on a default install: WordPress-gated videos deny logged-out visitors before the gate is reached, and on a members-only site the viewer is already identified, so the gate captured nothing the site did not already have.

Fix

  • Fresh installs now create the DRM licenses table. An inline comment inside the table definition made the statement fail silently, so new sites got every other table except this one and DRM license issuance could not work. Existing sites were unaffected.

Dev

  • Removed the ms_email_captures table, the /email-gate/submit and /email-gate/test-webhook REST routes, the mediashield_pro_email_captured action, and the five ms_email_gate_* / ms_email_retention_months options.
  • Collected email-gate leads are deleted on upgrade. Export them before updating if you still need them.

Compat

  • Requires MediaShield (free) 1.2.0. Install both updates together.

v1.1.0

June 3, 2026
New 4 Improve 6 Fix 7 Security 1 Dev 5 Compat 1

New

  • Complete customer and developer documentation set plus a project README.
  • Linked MediaShield video can render on a LearnDash lesson page when the lesson uses the shortcode.
  • Upload queue lifecycle hooks are wired into the free upload flow so every upload attempt is recorded.
  • GDPR exporter and eraser groups for the upload queue now surface and remove real data.

Improve

  • LMS metabox states that linking a video controls access and auto-completion only, and surfaces the exact shortcode to paste into the lesson.
  • Alerts page is fully usable on mobile, with a stacked card layout below 782px, 40px tap targets, badge severity, and correct pluralization.
  • Alerts "When" column shows the correct UTC-based relative time with a full-timestamp tooltip.
  • Alerts Video column reads "Site-wide" for events with no video context instead of "(N/A)".
  • "Mark as Safe" now dismisses that user's outstanding alerts, not just adds them to the whitelist.
  • Per-video email-gate default is aligned at 7 days across the PHP defaults and the React settings UI.

Fix

  • Heatmap "Playback Engagement" now populates from recorded session events on the scheduled hourly aggregation.
  • Per-video email gate now fires end to end for anonymous viewers via the new player access-type filter and a clean gate container.
  • Per-video LMS link now validates the lesson against active LMS adapters and rejects orphan IDs.
  • CSV export cannot be corrupted by PHP notices and passes an explicit escape character for PHP 8.1 and later.
  • PDF report status lookups resolve the correct job via UUID-keyed transients.
  • Detection Sensitivity radio no longer triggers a React console warning on every admin page.
  • Rapid-seek detection parses the stored UTC timestamp explicitly so elapsed time is correct regardless of server timezone.

Security

  • CSV direct-download route validates _wpnonce against wp_rest before streaming.

Dev

  • Registered _ms_access_type in the REST schema, saved via a dedicated per-video meta box with a nonce check.
  • The email-captured action now fires as mediashield_pro_email_captured, with the old name kept as a deprecated shim.
  • PHPStan now resolves the bundled EDD licensing SDK base class; PHPStan level 5 and WPCS are both clean.
  • Bundled the symfony/yaml runtime dependency so the architecture-invariants gate runs out of the box.
  • Added three critical regression journeys for LMS auto-complete, CSV and PDF export, and upload-queue lifecycle.

Compat

  • Requires MediaShield (free) 1.1.0. Install both updates together.

v1.0.0

Note 16

Note

  • Initial release.
  • Advanced watermark configuration with multiple text fields.
  • based video access control.
  • Email gate with cookie persistence and webhook support.
  • platform upload drivers (Bunny Stream, Vimeo, YouTube, Wistia).
  • and-drop support.
  • Playback heatmap analytics with 10-second bucket aggregation.
  • Realtime active viewer dashboard.
  • Suspicious activity detection (multi-IP, rapid seek).
  • ClearKey DRM key server and streaming license management.
  • Shaka Packager integration for local DRM packaging.
  • CSV data export (watch sessions, milestones, users, email captures).
  • Async PDF report generation via Dompdf.
  • Weekly digest email with analytics summary.
  • Milestone actions (tag, email, webhook).
  • EDD Software Licensing integration.