Platform Security Update: v13.7.2 Deep Hardening Complete
We have completed a comprehensive security hardening cycle across the entire GoSiteMe platform.
Security Improvements
- SQL Injection Prevention — All remaining raw SQL interpolation converted to parameterized prepared statements.
- WebSocket Auth Hardened — Removed dev fallback that accepted any token. Invalid tokens now properly rejected.
- Cookie Security — All cookies upgraded with Secure, HttpOnly, and SameSite=Lax flags.
- CSRF Protection — Referer checks added to 15+ destructive admin actions.
- Admin Access Control — Fixed authorization bypass that granted all admin users superadmin privileges.
- Path Traversal Prevention — Language file editor locked down to prevent directory traversal attacks.
No action required from users. These changes are automatically applied across all accounts.
Someone from somewhere
just launched website.com
Just now