Release notes
FloCMS follows semantic versioning. All five FloCMS packages, core, API, CLI, uploader and CAPTCHA, use exact version requirements, and composer.lock records the installed versions. composer install preserves them. The full history is in the changelog.
1.7.5
Released October 11, 2026.
- Multi-word page controllers. Requires
hostkurd/flocms-core2.2.2:/blog-postrunsBlogPostControllerand rendersviews/blog-post/, which is whatphp flo make:route BlogPostgenerates. In 1.7.4 these URLs answered 404. - Template directives accept parentheses.
@if(count($posts) > 0),@foreach(array_slice($posts, 0, 3) as $post)and@lang('key', ['name' => strtoupper($name)])compile correctly, and@forelse ... @empty ... @endforelseworks. Existing templates compile to the same PHP as before. - Security: single-use captcha codes. Requires
hostkurd/flocms-captcha1.1.0, now pinned exactly like the other packages:verify()removes the code on every check, so a code can't be guessed by retrying or reused by submitting the form again.
Existing sites get both with:
composer require hostkurd/flocms-core:2.2.2 hostkurd/flocms-captcha:1.1.0
1.7.4
Released October 11, 2026.
- Security. Requires
hostkurd/flocms-core2.2.1: only public, non-static actions on your controllers or your own base controllers can be reached from a URL. Methods inherited fromFloCMS\Core\Controllerare blocked. Before, a URL could reach that base controller's methods. APP_VERSIONand the version checks in the test suite now match the release.
Existing sites get the security fix with:
composer require hostkurd/flocms-core:2.2.1
1.7.3
Released October 11, 2026.
- Admin dashboard. Logging in redirects to
/admin/, which answered 404. It is now a small dashboard with the signed-in user, their role, a link to user management for roles allowed to manage users, and log out. - Role display names live in
config/config.php(Config::set('roles', ...)), shared by the dashboard and user management.
1.7.2
Released October 10, 2026.
- Requires
hostkurd/flocms-cli2.0.1, which fixes the hidden password prompt on Windows inuser:createanduser:password.
1.7.1
Released October 10, 2026.
- Welcome page. A new minimal design with the animated FloCMS logo. It still renders when a wrong
APP_URLbreaks theme asset links. - One-click APP_URL fix. On an
APP_URLmismatch, a local install offers a button that writes the detected URL to.env.
1.7.0
Released October 10, 2026.
- Commands come from Composer. The root
flofile is a three-line launcher for flocms-cli, socomposer updatedelivers new commands and fixes.php flo help <command>explains any command. - Your own commands. Classes in
commands/are commands, starting withphp flo login:unlock. - Migrations and seeders in
database/. The users table and the API tables are migrations. - Scheduler. One cron job runs the tasks in
config/schedule.php. - Maintenance mode with
php flo downandphp flo up. composer create-projectworks on PHP 8.1 again.
To upgrade an existing site, see the upgrade guide.