Skip to content

Changelog

What's new

This page is the public changelog for EchoThread — a chronological, human-readable log of every user-visible release. Each entry lists the features, fixes, and polish that shipped on a specific date, ordered newest first. We follow the Keep a Changelog convention so you can scan ship cadence at a glance or jump to a specific date for context on what changed.

Got an idea or a bug? Email hi@echothread.io.

Last updated

  1. The widget is readable on dark sites

    • On a dark site, the name and email boxes above the comment box could end up with dark grey text on a dark background — unreadable while you typed, and flagged as a contrast failure by accessibility tools. Your own page styles were overriding the widget’s; they no longer can. The same fix covers the report form.
    • The hint text inside those boxes, and the dot between the formatting hints, were both too faint to read on a dark background. Both now use the widget’s normal muted colour.
    • Links, @mentions, the selected sort option and the footer now lighten or darken your accent colour just enough to stay readable against the widget background. Buttons and other filled shapes keep your exact accent, so your brand colour is unchanged where it is a shape rather than a sentence. Accent colours that were already readable are left exactly as they are.
  2. Clearer spam decisions and explicit moderator corrections

    • Mark comments as spam individually or in bulk, while keeping ordinary rejections separate. Moderator corrections help identify repeated spam and rescue legitimate comments.
    • Spam explanations now distinguish confirmed reports from capped model scores. Short and non-Latin comments keep their review safeguards, and incomplete classifier responses are held for review.
    • The moderation dashboard and live demo explain the same scoring rules. AI-caught counts distinguish automatic catches from comments you mark as spam.
  3. Starter is $5 a month again, and the footer explains itself

    • Starter is back to $5 a month or $50 a year, down from $9 and $90. The plan is unchanged — three sites, 100,000 page views a month, no "Powered by EchoThread" line, per-site analytics, webhooks and API tokens — only the price moved.
    • If you are already paying for Starter, nothing changes and there is nothing to do: you keep the price you signed up at, as you always would have. If that price is higher than $5, you can switch to the new one from the billing portal whenever you like.
    • Annual is now $50 for the year, which works out at $4.17 a month — still ten months for twelve.
    • Pricing, billing and every upgrade prompt now open on the annual price instead of the monthly one, because it is the better deal and it was the one buried behind a toggle. Monthly is still one click away, and a link that names a term is honoured as it always was.
    • Emails about upgrading name the annual price first too, so the page and the email you arrived from agree.
    • If you own a site on the free plan and you are signed in, the widget footer now tells you so — one extra line, on your own page, naming what Starter costs and what it removes. Readers see exactly the footer they always have; the line is addressed to you and nobody else sees it.
    • The footer link now lands on a page that answers the two questions people actually arrive with: what this thing under the comments is, and — if the site is yours — how to remove the line. Previously it went to the homepage, which answered neither.
    • Once your widget has loaded for the first time, the site page offers Starter in one click. No waiting a week to be asked.
    • Adding a site now asks one question: is it for you, or for an organisation? It changes nothing about the site — both get exactly the same thing — and if you pick an organisation you are shown what Starter costs, with a "Skip for now" that takes you straight to your new site. Sites you already have are not asked and are left alone.
    • The email that goes out before a Starter trial ends now names your own site’s numbers from the trial — page views and approved comments — instead of describing the plan in the abstract. If there is nothing worth naming yet, the email says less rather than making something up.
    • The pricing page reads like a decision again. The free plan is five lines instead of ten, Starter opens with the thing most people buy it for — removing the "Powered by EchoThread" line — and the plan labels now say who a plan is for ("For one site", "For teams") rather than claiming one of them is popular. The full feature-by-feature table underneath is unchanged, and no plan lost anything.
    • Your first payment on a paid plan is refundable for 14 days, no questions asked — email us inside that window and we refund it in full, no reason needed. Cancel an annual plan partway through and we pro-rate the unused whole months back to you. The pricing page said to email us and the terms said payments were non-refundable; they now say the same thing, and the terms say it in full.
    • Checkout no longer asks for a VAT or tax ID, and no longer shows a promotion-code box. We do not issue promotion codes, so the box only ever sent people off to hunt for one that does not exist, and the tax-ID field asked every buyer a question that applies to very few. Tax is still worked out from your billing address exactly as before.
    • The pay button in Checkout now states what you are about to be charged, for how long, and that your first payment is refundable for 14 days — so the guarantee is in front of you at the moment you decide, not only on the pricing page you came from.
    • After you pay, the confirmation page now names your site and tells you the "Powered by EchoThread" line has been removed from it, instead of saying your plan is being activated. And the footer really is gone within a minute of the payment: your browser was allowed to hold the old answer for up to five and a half minutes, and now cannot hold it for more than thirty seconds.
    • Deleting your account now stops your subscription first. Before, deleting the account removed our records but left the subscription running at our payment provider — so you could end up still being billed by a company you could no longer sign in to. Your paid time is not cut short: the subscription stops at the end of the period you have already paid for. If we cannot reach the payment provider, your account is not deleted and we tell you, rather than leaving a subscription behind.
    • Cancelling from the billing portal now asks why, in one click from a short list. Answering is optional, and it is the only way we hear it — we do not email customers to ask.
    • If you start a checkout and do not finish it, the one email we send about it now picks up exactly where you left off — the same plan, the same term, the same tax already worked out — instead of dropping you back on the pricing page to start over. It works from any device and does not need you to be signed in.
    • That email now arrives a couple of hours later rather than the next day, and it names the price plainly. There is no discount in it, and there never will be: the price you were shown is the price. A checkout you leave open stays open for two hours before it lapses, and the email is how you get back in.
    • New sites now let readers comment without an account, and the create form says so with a checkbox you can clear before the site exists. It used to be off unless you found the setting, which meant a new site’s very first reader hit a sign-in wall — and almost nobody gets past one to leave a first comment. Every comment is still spam-screened before it appears, and you can switch it off at any time in the site’s settings. Sites you already have are not changed: whatever you set stays exactly as you set it.
    • Your dashboard can now post the opening comment for you. A site whose widget is live but has never had a comment gets a short list of what to try, and the first item — ask the question yourself — is now a button: pick the page, write it, post it. It appears on your site immediately, under your name, without going through the moderation queue you run.

    PricingBillingTerms

  4. "Powered by EchoThread" stays during the Starter trial, plus a Hostinger guide

    • The free 14-day Starter trial no longer removes the "Powered by EchoThread" line under your comments. The trial still gives you per-site analytics and webhooks with API tokens; removing the line is what a paid plan does, as it was before the trial existed. Sites in a trial that started before today show the line again from now on.
    • The trial banner, the pricing page, the trial-ending email and the trial-ended note now describe exactly what the trial includes, so nothing switches off at the end that you were not told about.
    • There is now a setup guide for blogs built with Hostinger Website Builder. Pasting the embed snippet into an Embed code element there leaves the post blank: Hostinger keeps the script but not the container it needs to fill, so the widget has nowhere to appear and nothing reports an error. The guide gives you a snippet that creates its own container, adds the discussion only to blog posts rather than every page, and gives each post its own thread.

    PricingHostinger guide

  5. Comment counts: your language, readable on dark themes, and a jump to the discussion

    • On WordPress, the count you place with the [echothread-count] shortcode — and the counts on your archive pages — now follow the plugin’s Language setting instead of always reading English. A Greek site reads “4 σχόλια”; on Auto, each visitor sees the count in their browser’s language, exactly like the widget already did.
    • A count dropped into a dark theme’s post meta no longer renders black on black. When the colour a count would inherit is unreadable against the background behind it, it is repainted with a readable one — and a colour you or your theme set is never touched.
    • Clicking a comment count now opens the discussion instead of the top of the post. A count that sits on a link — your theme’s comments link, or one you wrote — is pointed at the widget once its number arrives, so the thread is already in view; a link that already aimed somewhere specific, like a single comment’s permalink, is never redirected.

    WordPress setup

  6. WordPress widget survives WP Rocket and gains language and sign-in options

    • On WordPress, the comment widget now works with WP Rocket’s "Delay JavaScript Execution" setting. With it on, our script was held back until a visitor clicked or scrolled, so the comments area stayed empty and the discussion’s structured data was never added to the page. The plugin now tells WP Rocket to leave EchoThread’s scripts out of the delay — nothing to configure, and if you added cdn.echothread.io to WP Rocket’s excluded files as a workaround, it is safe to remove.
    • The same goes for WP Rocket’s JavaScript minification: the plugin now keeps EchoThread’s scripts out of it automatically, so a setting that used to quietly strip the discussion’s structured data from the page no longer can. No exclusion to add by hand.
    • The WordPress plugin can now pin the widget interface to one language — English, Korean, Italian, Simplified Chinese or Modern Greek — for every visitor, instead of following each reader’s browser. Comment text itself is never translated.
    • A new WordPress setting renders the social sign-in buttons as compact icons instead of the full "Continue with …" buttons, for themes with a narrow comment column. Screen readers still announce each provider by name.
    • The widget and the archive comment-count script each now load in two parts: a tiny loader and the app itself, saved under a name that changes with every release. The app is cached for a year, so PageSpeed Insights stops reporting “serve static assets with an efficient cache policy” for it, while the loader stays small and is revalidated often enough that a new release reaches your readers within minutes — they are never left on an old version.
    • Sites using their own widget domain get both changes too: the page-speed fix and updates within minutes, on the same schedule as everyone else.
    • Posting, editing or deleting a comment now updates the page’s structured data at the same moment — until now the description search engines and AI crawlers read kept describing the discussion as it was when the page loaded, until someone refreshed it. If you post the first comment on a post, the “Be the first to comment” note that used to stay up beside it is gone as well.
  7. Modern Greek, reply-aware counts, archive counts, and page-matched themes

    • The comment widget now speaks Modern Greek (Ελληνικά), including every button, prompt, error, notification, profile label and date. A reader whose browser is set to Greek sees it automatically, or you can set data-lang="el" to use Greek for everyone. The theme builder and example gallery include it too.
    • The number above your comments now counts every comment in the thread, replies included. It counted only the ones that start a conversation before, so a post with a good back-and-forth under it could say “3 comments” over five. Nothing about your comments changed — only the number that describes them.
    • You can now show comment counts on pages the widget itself never appears on: a category listing, your home page, a related-posts rail. Mark each spot, add one small script once, and every count on the page arrives in a single request. Whatever you already had in those spots stays exactly as it is if the count cannot be fetched, and the numbers match what the post itself shows.
    • On WordPress the plugin does this for you — turn on Archive comment counts in its settings. WordPress keeps its own tally of comments and stops updating it the moment EchoThread takes over, which is why your teasers have been showing the number you had on the day you switched, or zero. Now they show the real one.
    • Your comment widget now takes its colours from the page it sits on. Until now it followed each visitor’s device setting instead, so a reader whose phone or laptop was in dark mode got a dark widget on your light page — and nothing told you it was happening. It now reads the background behind it and matches: your light page keeps a light widget, for everyone. A page that paints no background of its own still follows the visitor’s device, as before.
    • If you would rather decide yourself, each site’s settings now carries a Widget theme choice — match my page, always light, or always dark. It applies everywhere that site’s widget appears, with no snippet to edit, and a theme set directly in your embed code still wins over it.
    • If you moved a Disqus archive onto a WordPress site running our plugin, your imported comments could stay invisible: the import filed each conversation under the identifier Disqus had used for it, while the plugin asks for the post by its WordPress id. The page found nothing and said “0 Comments”, even though every comment was safely stored and visible in your dashboard.
    • Imports now file every conversation under the page it belongs to, which is the one thing both sides agree on, so your archive shows up the first time someone opens the post — whatever identifier your site sends. Nothing about how you run the import changed.
    • Archives imported before this fix are being repaired. If a post of yours still shows no comments while your dashboard says otherwise, tell us the address and we will put it right.
    • Commenter names and post titles that arrived from an export written in Greek, Cyrillic, Hebrew or any other non-Latin alphabet now read as the words they are. They used to show up as a run of ampersand-and-number codes, because the export writes those letters that way and we stored what it sent instead of what it meant. Names and titles already stored this way are being decoded in place — nothing to re-import.
    • When an export records comment times in the site’s own timezone rather than UTC, we now work out the offset from the file itself and keep each comment at the hour it was actually posted, instead of reading the local clock as though it were UTC.
    • If your install snippet still carried the example page id from the optional-fields comment, every page on your site was asking us for the same conversation — so one page’s comments could appear under all the others. We now treat that example value as though it were not set, and each page gets its own thread again.

    Importing your commentsWidget theme builder

  8. Starter’s features free for 14 days, upgrade from Billing, resume an unfinished checkout

    • Every account now gets Starter’s features free for its first 14 days: no "Powered by EchoThread" line under your comments, the per-site analytics dashboard, and webhooks with API tokens. No card, no subscription, nothing to cancel. The clock starts the first time you open the dashboard, so existing accounts get theirs on their next visit, and it is one trial per account.
    • When the trial ends you are back on Hobby with nothing deleted: the line returns, analytics lock again, and the dashboard says so with a one-click way to keep Starter and a dismiss. Hobby stays free for your first site, forever, and the trial lends features only — the site count and page-view allowance stay those of your plan.
    • During the trial the dashboard shows a quiet status strip with the days left and the end date, the sidebar plan badge reads “Starter trial”, and your Billing page says when it ends.
    • Your Billing page now lets you upgrade to Starter, Pro or Business directly, with a monthly or annual toggle and the price for each shown before you click. It used to send you back to the pricing page to choose all over again.
    • If you open a Stripe checkout and close it without paying, you now return to a page that says so plainly — nothing was charged — with one button to resume that same plan and billing period, and a dismiss if you have changed your mind. It used to drop you on a blank pricing page as if you had never chosen.
    • The note about the "Powered by EchoThread" line on free-plan sites now takes you straight to the upgrade with Starter already selected.
    • The locked card for your own widget subdomain now shows the Pro price and starts checkout from there, like every other locked feature, instead of only linking to the pricing page.
    • A few days before your Starter trial ends, we send one email saying so: what switches off, that nothing is deleted and nothing is charged, and one link to keep Starter. It is one email per account, ever — there is no sequence — and it is not sent at all if you have already upgraded. Replying to it reaches a person.
    • When a site’s widget is live but nobody has commented yet, its card on the dashboard now lists the three things that most often get a first comment — post the opening question yourself, put the widget on the page readers already visit most, and, if guest comments are off on that site, turn them on — instead of only saying it is waiting.
    • Once your Starter trial has ended, the locked cards for analytics, webhooks and API tokens say so — “you had this until 20 September during your Starter trial” — so the change reads as what it is, with the same one-click upgrade beside it.
    • Once a site of yours passes ten approved comments while your account is on Hobby, we send one email with that number and what Starter would add for a site like it: one link, one email per site, ever, and not at all if you already pay. Replying to it reaches a person.
    • If your widget has been live on a site for a week and no one has commented yet, we send one email with the two or three things that usually get a first comment posted: ask the first question yourself, put the widget on your most-read page, and allow guest comments if readers currently have to sign in. It sells nothing, and it is one email per site, ever.

    BillingSee the plans

  9. Unlimited comments, comments on the blog, clearer plan limits, and one checkout email

    • Comment limits are gone on every plan, Hobby included. Nothing you or your readers post counts against a monthly number any more, and the 90% warning email for comments will never send again.
    • Sites you create on or after 1 October 2026 carry a monthly page-view allowance instead: 10,000 on Hobby, 100,000 on Starter, 1,000,000 on Pro, unlimited on Business. It is a soft allowance — we email you at 90% and again if you go over, and nothing is hidden, throttled or deleted.
    • Every site created before 1 October 2026 keeps unmetered page views for as long as it exists, on whatever plan you are on. The promise on the pricing page — we never paywall a site you have already set up — stands to the letter.
    • Starter is now $9 a month or $90 a year, up from $5. Anyone already subscribed to Starter keeps the price they signed up at for as long as they stay on it.
    • Every article on the EchoThread blog now ends with a live comment thread served by the same widget you would add to your own site — the product in use where you can see it, not a screenshot. Sign in or comment as a guest, reply to other readers, and react to what they wrote.
    • The blog’s comments follow the same rules as any EchoThread site: spam is filtered automatically before it reaches the page, and nothing is recorded about readers who only read.
    • Those comments are now part of each article’s page itself, not only drawn in by the widget: the approved discussion is written into the article’s HTML and described on the article’s schema.org markup as Comment entries with a comment count, so a search engine or an AI crawler that never runs JavaScript still reads what people said. The page updates on its own within about half a minute of a comment being posted, approved, edited or removed.
    • When you try to use a paid feature your plan does not include, such as webhooks or API tokens, the message now names the plan that includes it and what that plan costs, instead of only saying the feature is locked.
    • Your dashboard now shows a small, dismissible note when a free-plan site still displays the "Powered by EchoThread" line under its comments, and what Starter costs to remove it. Dismiss it and it stays gone across your devices; at most one note like this shows a week, and never before an account is a week old.
    • The number of sites is the one plan limit EchoThread enforces, and hitting it used to be a red line under the form telling you to upgrade at the pricing page — without saying what that costs or which plan you would need. The form is now replaced by a card that says exactly where you stand ("Hobby includes 1 site and you’re using it"), which plan raises it and by how much ("Starter includes 3 sites"), and its monthly price, with one button that starts checkout from there. A "Compare plans" link is beside it for anyone who wants to look at the whole ladder first.
    • The site you were adding is not lost: close the card, upgrade, and open "Add site" again and your name, shortname, and domain are still filled in.
    • If you talk to the API directly, the same refusal now carries a machine-readable code and fields alongside the sentence — the limit you hit, the plan you are on, and the plan and site count that would raise it — so a script can tell a plan limit apart from any other refusal without parsing prose.
    • If you start a checkout for a paid plan and leave it, you now get one email about it the next day, with a link that opens a fresh checkout for the same plan. Nothing is charged by an unfinished checkout and nothing changes on your account; the email exists because a payment page that put you off is something we want to hear about, and replying to it reaches a person.
    • It is one email, not a sequence: at most one every 30 days however many checkouts you start, never if you are already on a paid plan by the time it would go out, and there is no discount in it — the price is the price.
    • Comments you or your moderators post on your own site are published immediately instead of waiting in your own moderation queue. Your restricted-word rules still apply to everyone, staff included.
    • A comment’s reply count now counts only replies that are visible. A reply held for moderation used to make the widget offer "View 1 reply" with nothing behind it; the toggle now appears only when there is something to show.
    • An article on the blog had become unreachable: it was listed on the blog index, in the sitemap and in the RSS feed, but opening it sent you to a different post instead. It now opens where you expect, and every link pointing at it works again.
    • Several blog articles showed raw formatting marks in the middle of the text — stray asterisks around phrases meant to be bold or italic, backticks around file names you are meant to copy, and rows of dashes where a section break belonged. It was most obvious in bulleted lists, where the bold label opening each point is what makes the list quick to skim. Those now render as intended: bold and italic text, file names as code, and a proper divider between sections.
    • Related-article suggestions under a blog post could run one longer than intended, and the extra slot went to the least related article available. The list is now the length it should be.
    • Numbered and bulleted lists in several blog articles had collapsed into a single run-on paragraph, with the numbers left inline in the text. They render as proper lists again. Paragraphs that had run together are separated, and tag names quoted in the setup guides now show as code instead of showing their backticks.
    • Comparison tables on the blog now scroll sideways on their own on a phone. A wide table used to stretch the page instead, so the whole article shifted sideways and you had to scroll the page back to read the next paragraph. This affected 26 articles.
    • Setup guides that name an HTML tag or a framework component — things like the container element you paste the embed code into — showed an empty grey box where the name should be. The name is now visible and can be copied.

    See the plansYour usageRead the blogManage your sites

  10. Setup guides for seven more platforms, and a WordPress fix

    • The WordPress plugin’s recommended setting — "Replace the theme comments" — did nothing on a block theme. Block themes render comments as a block rather than through the older template hook the plugin listened for, so on every theme WordPress has shipped as its default since 2022 the setting saved happily and the site kept its native comments. It now replaces them, and the native comment form and list are gone from the page rather than sitting underneath.
    • On older classic themes, EchoThread no longer runs wider than the post above it. Replacing a theme’s comment template also discarded the wrapper that theme used to constrain the comment area, so comment lines could stretch to twice the width of the article. The replacement keeps the wrapper, and a theme that styles it keeps its layout.
    • If you installed the plugin, saved your key, and saw no change on your posts, this was why — update to 1.1.0 from your Plugins screen and nothing else needs changing.
    • There are now step-by-step setup guides for Ghost, Drupal, Joomla, Blogger, Squarespace, Wix, and Shopify. Each one names the exact file or setting to change, which identifier keeps a discussion attached to a post when its URL changes, and how to switch off the platform’s own comments so you do not end up with two comment boxes on the same page.
    • The Wix instructions changed, and if you followed the old ones it is worth redoing. Wix’s HTML embed element is an iframe, which meant comments appeared but readers could never finish signing in, and every post shared one discussion. The guide now uses Wix’s Custom Code setting instead, which puts the widget on your own page.
    • The Ghost and Squarespace instructions were out of date too. Ghost has shipped its own members-only comments since 5.0 and both of its default themes render them, so the guide now replaces that block rather than assuming there is nothing there; and Squarespace code injection lives on the Core, Plus, and Advanced plans, not the older plan names we still listed.

    Set up your siteGhost setup guideShopify setup guide

  11. Your own word list, your own bans, and threads that close themselves

    • Every site can now keep a list of words and phrases that must never publish unreviewed — up to 2,000 of them, one per line. Pick what a match does: hold the comment for review, or reject it outright. Matching ignores capitals, a * stands in for a run of characters with no spaces in it so one entry catches the variants, and it matches whole words, so "ass" does not fire on "class". Entries in Chinese, Arabic and Hebrew work as written, rather than quietly matching nothing at all.
    • Your list is checked before the spam filter, against the comment and against the name it would be posted under — so your rule decides, and a comment it catches never reaches the filter. Your queue says so: the comment is labelled as caught by your rule, with the exact word that matched, instead of being reported back to you as somebody else’s guess about spam. That label is for you and your moderators only; a commenter is never told which word caught them, or they could read your list back one attempt at a time. A match on someone’s display name always holds for review and never rejects, however you have set the list — a name is not a message.
    • You can now ban a commenter from a site, or trust one, straight from the comment in your queue. A ban stops that person commenting on that site and nothing else: never platform-wide, never following them elsewhere, and not the reader-side block that hides one person from one reader and tells nobody. Trust is the other direction — published without waiting in pre-moderation and without being held by your word list, though never past a word you set to reject outright, because that is a rule about what gets published rather than about who is writing. Everyone you have banned or trusted is listed on the site with the note whoever made the call wrote, and one button to lift it.
    • A ban can also take down that person’s still-visible comments from the last 30 days, if you ask it to. It is off unless you choose it, it works through a bounded slice of recent comments and tells you when there may be more, and those comments are rejected rather than deleted — so they sit in your rejected tab and you can put any of them back. Lifting the ban does not restore them for you: undoing a month of removals is a bigger decision than the button that would do it.
    • Sites can close discussions to new comments a set time after they start — 30, 60, 90, 180 or 365 days, or never, which stays the default everywhere. Existing comments stay visible and readable; only new ones stop. Nothing is written onto your threads to do it, so it is reversible: lengthen the window or switch it off and the affected threads reopen exactly as they were, and a thread you re-open by hand is left alone by the schedule afterwards. The widget explains a closed thread instead of just refusing one — and signed-out readers finally see that notice too, where they used to get a sign-in card that led nowhere.
    • Your list leaves with your data: the JSON export of a site now carries it, what a match does, and your auto-close setting alongside the comments. Who you have banned or trusted stays out of it — those are private judgements about other people, not settings, and an export is a file you might send to anyone. All three features are on every plan, Hobby included, with nothing to switch on and nothing extra to pay.

    Manage your sites

  12. We stopped measuring you, and staff can no longer open your account

    • EchoThread has always said "no tracking", and on the widget that was true — nothing we ship to your readers has ever set a third-party cookie or reported to an ad network. On our own site it was not. We recorded named steps as visitors moved through the pages, sign-up and checkout, and tied them together with a random identifier stored in the browser. All of it is gone: the code that sent it, the endpoint that received it, and the table it was kept in.
    • Nothing measures you on echothread.io now — not the marketing pages, not your dashboard. No page views, no steps, no visitor identifier, no analytics service of any kind. The one thing still written in your browser is which campaign or link first brought you here, so a sign-up can name its source; it is written once, never updated, records nothing about what you do, and reaches us only if you create an account. Send Global Privacy Control and even that is refused, and anything an earlier visit left behind is cleared.
    • The read-only support view has been removed too. It let an authorised member of staff load your dashboard as you see it, which was genuinely useful for diagnosing "my queue looks empty" without asking you for screenshots — but an account that cannot be opened is a stronger promise than one that can be opened carefully. Nobody here can sign in as you, see your screens, or act on your behalf, and there is no setting that turns it back on. If we need to see something, we will ask you.
    • Our internal tools still show the sites registered with us, the owner’s email address, plan and usage counts, and comment content where operating the service requires it — so we can answer a billing question or investigate abuse. The Privacy Policy and your Security screen now say exactly that, rather than implying we see nothing at all.

    Privacy PolicySecurity

  13. See what a locked feature looks like before you pay for it

    • Analytics, the audit log and webhooks used to be a locked card and a sentence. Each now shows a picture of the screen you would get: the comment trend and the threads driving it, a log of who changed what, the endpoints receiving your events and which of them is failing.
    • Nothing in those pictures is yours. Every figure, name and address in them is invented, they are labelled as samples, and they are built so they cannot read your account even by accident — a locked screen has no way to reach your data at all. A number you see there is never one you should act on.
    • They are pictures, not the feature. Each shows the shapes that matter rather than a copy of the real screen, so it is clear what you would be getting without it pretending to already be there. Screen readers announce them as illustrations and skip their contents, and they hold still if you have asked your system to reduce motion.
  14. What our staff can and cannot see in your account

    • When you write in about something that looks wrong on your screen — a moderation queue that shows empty, a widget rendering unstyled, a usage figure you believe is mistaken — we could only ever ask you to reproduce it for us. Screenshots, exports, "what does your Sites page say". Our staff can now open a read-only view of your dashboard and see it directly, which mostly means you stop being asked to do our diagnosing for us.
    • It is read-only in the strict sense. Staff cannot post, moderate, delete, change a setting, alter your plan, or act on your behalf in any way. That is enforced by the system rather than by a rule someone follows: a support session is refused before it reaches any code that could write, so there is no version of it that can change something by mistake.
    • No keys and no secrets. Your API keys, SSO signing secret, webhook secrets, personal access tokens and payment identifiers are withheld from every screen — not shortened, not partially shown. Staff can see that a key is configured; they cannot see any part of what it is.
    • Nothing about your account moves while we are looking. A support visit is not counted as a page view, does not appear in your analytics, does not consume any part of your plan, and does not mark your notifications as read.
    • Every session is recorded: who opened it, which account, the reason they gave for opening it, and each screen they viewed. Sessions last at most 30 minutes, cannot be extended, and the record of one is kept for 400 days. We do not send a notification each time — ask us and we will tell you from that record exactly what was looked at and when.
    • The full statement is in the Privacy Policy, and a shorter one now sits on your Security screen.

    Privacy PolicySecurity

  15. See the spam filter judge your own comment

    • The home page now lets you test the filter on your own words. Type a comment and the same classifier that screens comments on your site scores it and says what would happen to it: published, held for review, or filtered as spam. Nothing you type is stored anywhere.
    • It opens with three comments already scored: an AI-written one, ordinary link spam, and a real question. Each shows its score and what became of it, and clicking one drops it into the box so you can change a word and watch the score move. Those numbers come from the classifier itself, fetched when the page loads rather than written down somewhere — if a threshold moves, the page moves with it.
    • A scale underneath says what a score actually means: where publishing ends, where review begins, and where a comment gets filtered outright. Your own comment appears on it beside the examples.
    • It shows the reasons, not just the verdict. Whatever the filter noticed — a promotional link, templated phrasing, unusual link density — is listed beside the score, the same way it is in your moderation queue.
    • A high score on its own never comes back as spam there, because it never does in the product either. Hiding a comment outright takes a corroborating signal in the text as well; anything else waits for a human. The demo can only show you the three outcomes a real comment would actually get.
    • That corroborating-signal rule is now doing its job again on your site as well. Unmistakable spam — a wall of promotional links, a replica-goods pitch, a discount-code blast — is hidden outright rather than queued for you to confirm what you already know. Nothing is deleted, and restoring one is still a click.
    • It had quietly stopped: the filter limits how certain it will claim to be on its own evidence, that limit settled just under the level we were waiting for, and everything routed to a human instead. Nothing was ever wrongly hidden — the queue simply filled with things it should never have had to hold. It now follows that limit rather than assuming where it sits.
    • The safeguards are unchanged. A high score by itself still hides nothing, and comments in non-Latin scripts and very short comments are never hidden on the filter’s word alone — so a real comment does not disappear because the model misread the language it was written in.
    • The screenshot that used to sit at the top of the page is gone. It was five months old, and it showed a comment thread — which is what every comment platform shows — rather than the part that makes this one different.
    • Views and comments now say how they changed. Each carries the difference against the period immediately before it — the previous 30 days when you’re looking at 30 — so a number means something on its own instead of only in a chart.
    • A rise is marked, a fall is stated plainly. Traffic falling isn’t a fault — a quiet week, a post that has finished going round — so it’s reported without being flagged as a problem.
    • The comparison is withheld whenever it would mislead. If we weren’t recording for the whole of the earlier period, comparing against it would show our own start date as your growth, so nothing is shown at all rather than a number that reads as real. The same applies when there’s nothing to divide by: a period that starts from zero says "new" instead of an impossible percentage.
    • Export CSV takes whatever range you’re looking at as a spreadsheet: one row per day, with views and comments. Today’s row is marked as still being counted, so a part-finished day never gets averaged in as a whole one, and days from before we started recording your site are left out rather than exported as zeroes.
    • The page now says how far back daily history goes. Ninety days was always the limit; the only way to notice was that no button offered more.
    • Top threads now shows views per page, not just comments. Until now the only view count anywhere was for the whole site, so there was no way to tell a page that a thousand people read and nobody replied to from one nobody opened. The list is still ordered by comments; views sit beside them.
    • A dash in that column means we don’t have view data for that page yet, and it says so. Views are counted per page by the widget itself, so the column fills in as visitors load the current version — we’d rather show a gap than print a confident zero next to a page that was being read all week.
    • A new Comment outcomes panel answers the question the comment count never could: of everything that arrived, how much was spam. It shows the rate, then the split — approved, pending, spam, removed — as a bar you can read before any of the figures.
    • Outcomes are counted against the day a comment arrived, not the day you got round to moderating it. Clearing a weekend backlog on Monday used to be the only way to make Monday look like a spam wave; now the spam lands on the day it was actually posted, which is the only way the rate means anything.
    • The panel says how many days it actually measured, and says "not recorded yet" rather than showing zeroes for days from before we were counting. No spam and no measurement are different things, and only one of them is good news.
    • Comments now split into conversations started and replies, so you can tell a page that got twenty separate remarks from one that got a single thread twenty deep.
    • The CSV export carries all of it — replies and the outcome split per day, alongside the views and comments that were already there. The original columns kept their names and their order, so anything already reading the file still works.
  16. Every screen a site has, reachable from the site

    • The sidebar's Current site section now lists every screen a site has: Settings, Moderation, Analytics, Webhooks, Single sign-on, Custom domain, Audit log, Data retention, and Import. Analytics, single sign-on, the audit log, data retention, and import were all live, but none of them had an entry in the sidebar — the only way to reach one was to already know its address.
    • The site page has a new "Manage this site" row carrying the same destinations, labelled so it reads as a map of the site rather than a row of buttons competing with the next step the page recommends.
    • Widget domain is in both for the first time. The panel sat at the bottom of the site page with nothing anywhere linking to it, so you had to scroll past four cards to discover it existed; the new link jumps straight to it.
    • That screen also stopped offering something we can't do. It used to present two ways to give a site its own hostname: one on echothread.io, and one on a domain you own — comments.yoursite.com, say. Only the first was ever real. The second asked you to add DNS records and prove you controlled the domain, then said we'd switch it on within a business day. We couldn't: serving the widget from a domain you own needs a certificate we have no way to issue for it. That option is gone from the screen, and from the pricing page.
    • What remains is the part that works: a hostname on echothread.io for each site, like yoursite.echothread.io. You pick the name and it's live — no DNS to add, nothing to prove, no wait on us.
    • If the screen can't offer you a hostname yet, it now says so and tells you where your widget loads from in the meantime, instead of looking empty.
    • No site changed address and no embed code needs updating. Nobody was serving a widget from their own domain, because nobody could.
    • Analytics kept whatever numbers were true when you opened the tab. The page fetched once and never asked again, so it read like a report that updates once a day — it doesn't. Views are counted every minute and a comment is counted the moment it's posted. The page now says how old the numbers are, refreshes itself while you're looking at it, and has a Refresh button when you don't want to wait.
    • Browser tabs now name the site you're working on — "Travel Project · Analytics" rather than just "Analytics". Every site screen looks about the same, so with a few tabs open there was no way to tell which site a tab was editing without clicking into it.
    • Analytics stopped ending every chart in a phantom drop. The last point on the chart was always today — a day that hasn't finished — sitting next to whole days, so it always looked like traffic was falling, and worst first thing in the morning when only an hour or two had been counted. Today now appears above the chart as "Today so far" instead, where it reads as a running total rather than a decline.
    • A chart with only one day left in it drew a peak rising and falling around that day. Nothing rose or fell — there was one day. It now draws as a level line.
    • Screens your plan doesn't include are still listed rather than hidden — opening one tells you which plan adds it, so you can see what the product has without reading the pricing page.
    • The sidebar now highlights exactly the screen you are on. Standing on a site’s Analytics used to leave My Sites, Settings, and Analytics all lit at once, so the highlight told you nothing about where you were.
    • Screens your plan doesn't include now name the price, not just the plan. Analytics reads "On Starter, $5/mo" rather than "Upgrade to the Starter plan" — so you can decide whether it's worth it without leaving the page to look it up.
    • The upgrade button starts checkout for exactly that plan instead of sending you to the pricing page to choose again. Compare plans sits beside it if you would rather see everything first.
    • The sidebar marks those screens with the plan that adds them. They used to look identical to the ones you already have, so the only way to find out was to open one.
    • Every screen belonging to a site now names that site at the top — Moderation, Analytics, Webhooks, single sign-on, custom domain, the audit log, data retention, and import. They all used to open with nothing but a Back link, so landing on one from a bookmark, a second tab, or a link someone sent you gave you no way to tell which site you were about to change.
    • Analytics opens on the numbers now. Views, comments, and how often a view turns into a comment sit across the top as three figures, each with the shape of its own trend behind it, so the answer to "how are we doing" is the first thing on the page rather than something you read off a chart.
    • Comment rate is new: comments per 100 views over whatever window you're looking at. It's the number that says whether traffic is turning into conversation, which neither a view count nor a comment count answers on its own. When there are no views to divide by it shows a dash — unknown is not the same as zero.
    • The charts will now tell you what any single day was. Hover anywhere and the day and its value follow your cursor; the highest day and the most recent day are marked so the eye lands on them without hunting. Arrow keys do the same thing without a mouse.
    • Charts also gained the scale they were missing. Values run down the left edge, so a line is readable as quantities rather than only as a shape, and the line itself no longer thickens and thins across the width on wide screens.
    • A site's first day no longer shows an empty box. The chart genuinely has nothing to draw until one full day has passed — a part-finished day plotted beside whole ones always reads as a crash — but the page now leads with the views and comments counted so far today instead of a dashed rectangle, and says in one line when the first full day arrives.
    • A summary tile covering a single day draws as a level line rather than a peak rising and falling around it, matching the fix the larger charts already had.

    Pricing

  17. Plan features across every tier

    • Every plan's feature set is now staged clearly by tier, not just its usage limits. Starter and above include webhooks, the public read/moderate API, and the analytics dashboard. Pro and above add shared-secret SSO, a custom widget domain, and the ability to assign Moderator seat roles. Business and Enterprise add the audit log and data retention controls. The full breakdown lives on the pricing page's comparison table.
    • Page views are now unlimited on every tier, including Hobby — nothing about your traffic counts toward a plan limit. Comment volume and site count are the only usage limits that apply from here on.
    • Sites with an active custom widget domain (Pro and above) now have the comment widget call that domain for every API request — loading comments, posting, sign-in, and everything else — instead of quietly falling back to api.echothread.io no matter what the snippet pointed at.
    • The install snippet on your site's page — and the one a developer sees when you send them setup via a secure link — now points its <script> tag at your active custom domain too, instead of always showing cdn.echothread.io. Copy it fresh and it matches what's actually live.
    • No setup changes needed: this is automatic for every site with an already-active custom domain, and for any new one activated going forward.
    • Team seats added to a site without an explicit role assigned are now badge-only until an owner on a Pro plan or above picks Owner or Moderator for them — matching how seat roles were always meant to work, so a freshly-invited teammate never has more access than the site owner intended before a role is chosen.
    • Revoking a personal API token now takes effect immediately and can never be undone by an in-flight request that was already using the token — the moment you revoke a token, it stops working everywhere, full stop.
    • If an EchoThread account is disabled, any personal API tokens tied to it now stop working across the public API right away, the same as they already did for the dashboard.
    • The analytics chart no longer draws a flat line back to the start of the range for days that came before we started recording traffic on your site. Picking 30 or 90 days on a site with a shorter history used to look like a traffic collapse; the chart now shows only the days that were actually being counted, with a note saying since when. The same date appears on the empty state, so a silent chart tells you whether there is genuinely no traffic or simply no history yet.
    • Setting a custom widget domain now walks you through it as a numbered checklist instead of a flat list of records. It shows all three DNS records you need — including the certificate record, which you previously had to get from us by email — in the order they have to be created, each with a one-tap copy.
    • A new “Check my records” button reads your DNS live and tells you, record by record, whether we can see it: found, not there yet, or present but pointing somewhere else. If a value is wrong, it shows you what it actually found, so a trailing dot or a pasted-in typo is something you can spot and fix in seconds rather than discover a day later.
    • The checklist explains the order it asks for. Your domain becomes a CNAME and the two validation records sit underneath it, which some DNS providers refuse to serve — so the validation records go in first and the domain itself goes last.
    • Once every record on your side passes, the panel says so plainly and tells you the work is with us: we issue the certificate and switch the domain on within one business day. Activation was never automatic and still isn't, but you no longer have to guess whether you are waiting on us or we are waiting on you.
    • Once your domain is live, the panel keeps showing the certificate record with a warning to leave it in place. That record is what renews your certificate automatically — deleting it during a DNS tidy-up would have taken the domain offline up to a year later with no warning.
    • Checkout, invoices, and the billing portal now describe each paid plan by what it actually includes — site count, comment volume, and the specific features on that tier. Starter and Pro were still advertising monthly page-view ceilings that stopped applying when page views became unlimited on every plan, and none of the plans listed their features at the point where you decide whether to buy one. Both are fixed.

    Pricing

  18. Assign Owner or Moderator roles to your team seats

    • Pro plans and above now have a Custom widget domain panel on each site's settings (Site settings → Custom widget domain): point the comment widget and its API calls at a subdomain you control, like comments.example.com, instead of api.echothread.io / cdn.echothread.io.
    • Enter your domain and we give you a CNAME record and a TXT ownership record to add at your DNS provider, each with a one-tap copy button. Activation is manual, not automatic: once the records are in place, our team verifies and activates the domain within one business day — nothing about certificate issuance or DNS validation happens on its own.
    • Once your domain is active, the panel shows your embed snippet updated to point at it, so you can copy it straight into your site. Removing a custom domain asks you to confirm first and immediately falls back to api.echothread.io / cdn.echothread.io — remember to update your embed code afterward.
    • On every other plan, the custom domain panel explains that it's a Pro feature and links to plans that include it.
    • Business and Enterprise plans now have a Data retention screen for each site (Site settings → Data retention): pick Forever, 2 years, 1 year, or 90 days for how long comments stick around before they're permanently deleted. Forever is the default for every site, so nothing changes until you choose a shorter window. Shortening the window always asks you to confirm first and says exactly what will be deleted; widening it back out saves right away. On every other plan, the screen shows the current setting (Forever) and explains that choosing a retention window is a Business feature.
    • Business and Enterprise plans now have an Audit log screen for each site (Site settings → Audit log): a newest-first record of who did what — moderation actions, site settings changes, webhook and API token activity, SSO secret rotations, and team seat changes.
    • Every audit log row shows when it happened, who did it (or "System" for automated actions), what the action was, and what it was done to. Filter by action or by actor ID to narrow a long history down, and clearing the filters brings back the full list.
    • Long audit histories page with a "Load more" button rather than loading everything at once, and a filtered-to-nothing view tells you how to clear the filter instead of leaving you looking at a blank panel. On every other plan, the screen explains that audit log is a Business feature and links straight to plans that include it.
    • Every site's Team & roles panel (Site settings → Team & roles) now shows a role next to each of your 5 team seats, including your own.
    • Pro plans and above can change a seat between Owner (full access) and Moderator (can review and act on comments, but not billing or site settings) right from that dropdown — the change takes effect immediately, no page reload needed.
    • On every other plan, every seat still shows as Owner and the role selector is disabled with a note on how to unlock Moderator — inviting and removing teammates keeps working exactly as before, on every plan.
    • The 5 free team seats are unchanged and unmetered on every tier — this only adds a role to seats you already had.
    • If your site only has one owner, that seat's role can't be changed — the site always needs at least one, and the selector explains why right there instead of letting you submit a change that would fail.
    • The /pricing comparison table now has rows for "Webhooks & public API access", "Analytics dashboard", "SSO (shared-secret)", "Audit log", and "Data retention controls" — all five were already live in the dashboard for their respective plans, but weren't represented on the pricing page until now. Audit log and data retention controls are false on Hobby, Starter, and Pro, and true on Business and Enterprise.
    • The Starter plan card now lists webhooks, personal API tokens, and the analytics dashboard among what it adds over Hobby, the Pro plan card now lists shared-secret SSO among what it adds over Starter, and the Business plan card now lists the audit log and data retention controls among what it adds over Pro.
    • We removed the line claiming every plan has the same features and only the limits change — it stopped being true once Starter added webhooks, API access, and analytics, so the page now describes what each tier actually includes.
    • The SSO row links straight to the SSO integration guide, and the pricing page now says plainly what the feature is: your own backend HMAC-signs a small identity payload and hands it to the widget, so a visitor lands signed in with no separate EchoThread login. It is not an OIDC or SAML integration — there is no identity-provider connection to configure.
    • The pricing page now also has a "Team seats" row (5 on every tier, including Hobby) right next to a new "Restrict a seat to Moderator-only" row (false on Hobby and Starter, true on Pro and above) — and says plainly, in the comparison-table intro and on the Pro plan card, that seat count never changes by tier. What Pro adds is the ability to narrow a seat to Moderator, not more seats.
    • The pricing page now says plainly what the audit log covers — moderation actions (comment approvals, rejections, and deletions), settings changes (site settings, webhooks, and team seat roles), credential actions (personal API token creation and revocation, SSO secret rotation), and entitlement changes — and lists the four retention windows a Business or Enterprise site can choose from: forever (the default on every plan today), 2 years, 1 year, or 90 days.
    • Our published product capabilities contract (/.well-known/product-capabilities.json) now lists which tiers include webhooks & API access, analytics, SSO, the Moderator seat role, the audit log, and data retention controls, for tools that read it programmatically.
    • The /pricing comparison table now also has a "Custom widget domain" row, false on Hobby and Starter and true on Pro, Business, and Enterprise, and the Pro plan card lists it among what Pro adds over Starter — the feature itself is the Custom widget domain panel described above, now represented on the pricing page too.
    • The pricing page says plainly what's self-serve and what isn't for a custom domain: adding the CNAME and TXT ownership record at your own DNS provider is instant, but verifying that record and activating the certificate is done by hand by our team, typically within one business day. We don't claim automatic or instant provisioning anywhere on the page.
    • The product capabilities contract now also lists which tiers include the custom widget domain, with that same self-serve-DNS/manual-activation distinction, for tools that read it programmatically.
    • The Data retention screen described above is now backed by a tested, automated nightly job on our infrastructure that actually deletes comments older than your chosen window, rather than only recording the setting. We're bringing it online for existing sites in a controlled rollout rather than all at once, since it's an irreversible deletion of data — the same deliberate, manual-activation approach we use for custom domain cutovers above. Nothing changes on the Data retention screen itself, and sites still set to Forever are never affected.
    • Your Sites page now opens with the first 25 sites instead of waiting for every site in your account. Keep scrolling, or use Load more sites, to continue through the list while the total stays visible.

    PricingSSO docsManage your sites

  19. API tokens, webhooks, SSO, analytics, and unlimited page views

    • Starter plans and above now have an Analytics screen for each site (Site settings → Analytics) showing page views and comments over time, so you can see how a site is trending without leaving the dashboard.
    • A small sparkline and running total sit above each full chart so you can see at a glance whether views and comments are trending up or down before reading the day-by-day detail.
    • Pick a 7, 30, or 90 day window and both trend lines redraw for that range — the same two metrics, just zoomed to a different span.
    • A top-threads list ranks which conversations got the most comments in the window you're looking at, with a link straight to the page for each one.
    • A brand-new site shows an explicit "no data yet" message instead of a blank chart, so it's clear you're waiting on real traffic, not looking at a broken graph.
    • There's a full reference for EchoThread's public API at /docs/api — every read and moderate route, with the exact request and response shape for each one, how cursor pagination works, and what every error response looks like.
    • It also says plainly what the API doesn't do: there's no way to create a comment through it. Comments are only ever posted by a real visitor through the embed widget — the public API is for reading and moderating what's already there.
    • Starter plans and above can now generate personal API tokens from Account → API Tokens to authenticate scripts and servers calling EchoThread's public API — separate from the signed-in session your browser uses.
    • A token's plaintext is shown exactly once, right after you create it, with a one-tap copy button. After that, EchoThread only ever shows a masked fingerprint, so store it somewhere safe the first time.
    • Give a token an optional expiry (30 days, 90 days, or 1 year) and it stops working on its own — no need to remember to come back and revoke it.
    • Revoking a token asks for confirmation and takes effect immediately, and every token you've ever created — including revoked ones — stays listed so you always know what has access.
    • If your plan changes, any tokens you already created keep working and stay fully visible and revocable — only minting a new one requires the feature.
    • Starter plans and above can now subscribe an HTTPS endpoint on your own server to comment and thread events — new comments, approvals, rejections, deletions, and new threads — and get a signed request the moment each one happens.
    • Every endpoint gets its own signing secret, shown once when you create it, so you can verify a delivery really came from EchoThread before you trust it.
    • A "send test event" action lets you confirm your endpoint and secret are wired up correctly before relying on either, and a failing badge on an endpoint tells you when recent deliveries aren't getting through — separate from whether you've turned it off.
    • Publishers can now pass a signed identity from their own login system into the comment widget, so a reader who is already signed in on your site sees their name and avatar in the comments without a separate sign-in step.
    • There is no sign-out button in this state — the identity belongs to your site, not the widget, so signing out happens wherever your readers already sign out.
    • If the signed identity can't be verified (for example, it's expired), the widget quietly falls back to its normal sign-in options instead of failing to load — comments always render.
    • Pro plans and above can now manage that single sign-on setup from Site settings → Single sign-on, without waiting on support — your signing secret is minted automatically the first time you visit the page, stays masked until you choose to reveal it, and a one-tap copy button puts it on your clipboard.
    • Rotating the secret is behind a confirmation that explains what happens in plain language: your previous secret keeps verifying sign-ins for 24 hours after rotation, so you have time to deploy the new one before the old one stops working — no outage for your readers mid-rotation. The new secret is shown right away so you can copy it in the same moment you generate it.
    • There's now a complete SSO integration guide at /docs/sso for wiring up that signed-identity handoff: the exact payload your backend signs — id, email, name, and avatar — with a worked, copy-pasteable signing example in both Node.js and PHP, the two stacks publishers ask about most.
    • It also covers the parts that are easy to get wrong: the signed payload is only valid for 5 minutes, so it has to be generated at render time rather than cached, and passing it to the widget takes three new attributes on the embed snippet alongside your usual API key.
    • Page views are no longer metered or capped on any plan, including Hobby. There's no monthly page-view number to watch, no warning email for traffic, and no upgrade prompt for a busy day — pricing and plan limits are based on sites and comments instead.
    • Your billing page keeps a running count of page views for each site so you can see your traffic, but it is informational only — it was never something you needed to stay under.
    • If you're on a paid plan, this changes nothing about your bill: page views were never the thing you were paying for.
    • The theme builder's language menu now includes Simplified Chinese (简体中文), so you can see how the widget looks in every language it speaks before you copy the snippet. Chinese shipped in the widget last week but was missing from this preview.
    • The sample conversation in the preview now reads in whichever language you pick, so a Korean, Italian, or Chinese preview shows a realistic thread instead of translated buttons around English placeholder text.

    Public API docsSSO docsAPI tokensPricingTheme builder

  20. Simplified Chinese, and a clearer picture of your plan

    • The widget interface is translated into Simplified Chinese (简体中文), alongside English, Korean and Italian. Visitors whose browser is set to Chinese see it automatically — there is nothing to configure. To pin one language for everyone instead, set data-lang="zh" on the container.
    • Chinese text is set in a native font stack with the extra line spacing dense characters need, and long comments wrap correctly rather than running past the edge of the widget. As always, only the widget's own interface is translated — comments are shown exactly as they were written.
    • Your billing page now shows this month's page views and comments for each of your sites, measured against what your plan includes. Until now the only signal was a single email at 90%, and there was nowhere to look the number up afterwards.
    • Your sites list shows the same page-view figure on each card, so you can spot the busy one without opening anything.
    • If a site passes a limit, the dashboard says so — which site, which limit, and how far past. Percentages are shown as they really are, so ten times over reads as 1,000%, not a full bar.
    • You now get a second email the first time a site goes over a limit each month, not just the one at 90% — and a further one each time the overage doubles, so a site that ends up ten times over hears about it rather than drifting. All of them are informational: going over has never switched anything off, and still doesn't — comments keep working, nothing is hidden, and nothing is deleted.
    • Each site's own page also shows its usage, so you can check one site without opening billing.
    • Counters reset at the start of each calendar month, and the reset date is shown next to them.
    • Choosing a plan is easier too: each paid plan now lists only what it adds to the one below it, rather than repeating the same feature list on every card. The two or three lines that genuinely differ are the only ones left to read.
    • The pricing page now explains what counts as a page view and roughly what kind of site lands in each range, so you can work out which limits you need before signing up instead of guessing.
    • Enterprise now says plainly what it is for — contracts, procurement and security review, not extra capacity. Business already has no limits.
    • On a phone, plans are swiped through one at a time instead of stacked into one very long page.

    Widget languagesYour usageCompare plans

  21. Option to turn off the widget's automatic structured data

    • If you render EchoThread's schema.org discussion markup yourself server-side, the widget was always injecting its own copy too, leaving two JSON-LD blocks on the page. Set data-structured-data="false" on the widget container and the widget keeps handling comments normally while leaving structured data entirely to you.
    • The discussion structured data (both the widget-injected and server-rendered versions) now also credits EchoThread as the publisher, so AI answer engines and search crawlers can trace the discussion back to its source.

    Structured data docs

  22. Fixed: several ways you could still get signed out early

    • Reloading the dashboard, or coming back to a tab you'd left open, could sign you out even though your session was still good — a gap in how the page restored your sign-in state. Sessions now stay signed in for the full 30 days across reloads, the same way commenting sign-in already worked.
    • A brief hiccup on our end — a slow moment, a restart during an update — no longer ends your session. Your browser used to treat any failure to renew a session as "you're signed out", so a few seconds of trouble signed you out for good. It now holds onto your session and simply tries again.
    • Keeping the same site open in two tabs no longer signs you out. Both tabs renewing a session at the same moment looked like a stolen sign-in, which ended every session you had — dashboard, phone, and every site you comment on. Tabs now hand off to each other, and in the rare case we do end a session to keep your account safe, it ends that one sign-in instead of all of them.
  23. Commenting now stays signed in

    • Sign in once and you'll stay signed in on that site until you actually sign out — no more getting logged out mid-conversation and having to sign back in just to post a reply.
    • Works the same way across every sign-in option: magic link, Google, X, and Facebook.
    • Signing out now properly ends that session on our servers, not just in your browser.
  24. Large imports finish, and imported comments actually show up

    • Importing a big archive no longer stops partway. A large export used to be cut off by a request timeout after a few minutes, quietly leaving most of your threads behind with nothing to tell you it had happened. Imports now run in the background and report live progress — you can close the page and come back.
    • If an import is interrupted, it says so, and re-uploading the same file picks up where it left off instead of creating a second copy of everything.
    • Imported comments now appear on WordPress sites. An export identifies each thread by its page address while the WordPress plugin identifies it by post, so imported discussions could land on a thread the widget never looked at. Both sides now resolve to the same thread, in either order — import first or install first.
    • Re-importing the same file no longer duplicates comments, and comment text imported from WordPress renders as text instead of showing raw markup.

    Import your comments

  25. A moderation queue that keeps up with big sites

    • The pending queue no longer drags every comment body on the site across the wire to build a single page. Sites with thousands of comments stopped timing out, and "Load more" pages all the way to the end instead of stranding you mid-queue.
    • "Open comment" in the moderation queue now deep-links to the exact comment on your page instead of dropping you at the top of the bare page URL.
    • Threads self-heal their page URL. If the very first visitor loaded the widget on a homepage or a redirect, the thread used to keep that URL forever and every comment link pointed at the wrong page — later views now correct it to the real article URL.
    • For sites that already collected stale URLs, a new maintenance pass repairs them from your sitemap rather than waiting for a visitor to trigger the fix.
  26. Your comments are now readable by search engines and AI answer engines

    • Every thread now publishes schema.org `DiscussionForumPosting` structured data, with each comment nested as a `Comment` — so the discussion under your article is machine-readable, not just the article.
    • It ships two ways: the widget injects the JSON-LD on the page for standard crawlers, and a server-rendered endpoint returns the full approved-comment tree for publishers who want to include it server-side, where non-JS AI crawlers can see it.
    • Approved comments only. Pending, rejected, and spam comments are never exposed in structured data.
  27. Buttons you can actually see

    • Secondary buttons across the dashboard and site now meet the WCAG 1.4.11 non-text contrast bar — their borders are visible on light backgrounds instead of nearly vanishing.
  28. Checkout fixed, and watched continuously

    • Fixed a bug that made every attempt to start a paid plan fail. Upgrading works again.
    • A synthetic monitor now runs the real checkout flow against production on a schedule, so a broken upgrade path alerts us instead of quietly blocking sign-ups.
    • Production now refuses to boot on a Stripe sandbox key, which removes a whole class of billing misconfiguration.
  29. Passkey sign-in fixed

    • Passkey (WebAuthn) enrollment failed verification for everyone; registering a passkey now works, and the case that broke it is covered by a spec-vector regression test.
  30. A public roadmap you can vote on

    • The roadmap is public: vote-ranked items in status lanes, so you can see what is planned and push what matters to you up the list.
    • The feedback form now asks what kind of feedback you are sending (bug, feature request, or something else) and asks before anything you write is shown publicly.
    • New DMCA policy and counter-notification process, plus a plain-language privacy notice covering roadmap votes and feedback.

    Public roadmapPrivacy Policy

  31. Theme builder, spoiler polish, and free reply notifications

    • New theme builder: paste your page URL, tune the widget colors against a live preview, and copy the finished snippet. Reachable from the homepage, docs, widget gallery, and your site settings.
    • Spoilers got a frosted-blur treatment instead of the old striped block, and emoji reactions now pop on hover and click.
    • Spoiler support is a per-site toggle in the dashboard — turn it off for sites where masked text is noise.
    • Composer polish: Material icons, tactile button states, and on mobile the Post button stays on the toolbar row instead of wrapping.
    • The notification dropdown no longer gets clipped on mobile.
    • Pricing is clearer about what free means: reply email notifications are included on Hobby, there are no ads and no tracking on any plan, and removing the EchoThread footer link is the paid upgrade.

    Theme builderPricing

  32. Widget gallery and adaptive theming

    • A public widget gallery shows the widget in each of its themes, so you can pick a look before installing.
    • Adaptive theming: a custom accent color is now honored on custom backgrounds instead of being overridden by the preset palette.
    • Fixed Google sign-in in browsers with strict cross-origin popup isolation, where the popup could hang after a successful sign-in.
    • GitHub was removed from the dashboard sign-in options — owner accounts use Google or a magic link. (Commenter sign-in options are unaffected and configured per site.)

    Widget gallery

  33. Commenters can sign in with X or Facebook

    • X (Twitter) and Facebook join Google and GitHub as commenter sign-in options in the widget.
    • You choose which providers your readers see: a Sign-in methods control in the dashboard toggles each one, with at least one always enabled so no site can lock its readers out.
    • Neither provider reliably returns an email, so a returning reader is matched to a stable identity without one — the same person stays the same commenter.
  34. Tax handled at checkout

    • Checkout now calculates tax from your billing location automatically.
    • Business buyers can enter a VAT or tax ID during checkout and get a compliant invoice.
    • The billing address you enter is kept on file, so renewals and the billing portal stay tax-correct.
  35. The widget speaks your readers' language

    • The widget UI is localized (English, Korean, Italian) and picks a language per visitor from the browser. Set `data-lang` to pin one language; anything unrecognized falls back to English. Comment content itself is never translated.
    • Moderation is no longer biased against non-English comments: a high spam score alone routes a comment to review instead of hiding it, and auto-hiding now requires a corroborating content signal such as a link or promo pattern. This started with a friendly Korean comment being auto-hidden as spam.
    • Approving a comment the filter flagged now teaches the spam classifier it was wrong.
    • Docs, README, and the in-product install snippet all document the language options.

    Localization docs

  36. WordPress plugin live, Terms of Service, and a fixed sign-in popup

    • The WordPress plugin is published in the WordPress.org directory as "ThreadBridge Comments for EchoThread" — install it from your WordPress admin, paste your shortname, and pick where comments render.
    • A full Terms of Service page, and gaps closed in the Privacy Policy.
    • Fixed commenter sign-in on embedded sites: the sign-in popup now returns your session to the page you were reading instead of stalling after a successful sign-in. The origin it returns to is signed and validated against your site, so the fix does not open a redirect hole.
    • Subscription webhooks now tolerate newer Stripe API versions, so plan changes keep syncing rather than silently drifting.
    • A public product-capabilities endpoint states what EchoThread does — what is free, what is paid, what data is handled — in a form other tools and AI agents can read directly.

    Terms of ServicePrivacy Policy

  37. Setup a non-developer can finish

    • No-code install guides for Squarespace, Wix, and Ghost, plus a platform picker in the dashboard that deep-links you to the guide for your platform.
    • Install detection: the dashboard now says "Widget detected on yourdomain.com" with a first-seen time, instead of leaving you to reload and hope.
    • "Send setup to your developer": generate a secure expiring link (or email it) that opens a no-account page with the snippet, where to paste it, and the key. Your key is never put in the email body.
    • Your registered domain is now enforced as an allow-list on embed endpoints, so an API key copied out of your page source does not work from someone else's site.
    • One page is one thread again: `/post` vs `/post/`, `http` vs `https`, `www` vs apex, and `?utm=…` links no longer split a single page into separate threads. Existing threads are matched on both the old and new keys, so nothing is orphaned.
    • The install flow is localized and hardened for screen readers, and states in plain language what data is handled, with a link to the DPA.

    Install guides

  38. EchoThread 1.0 — out of beta

    • EchoThread is now generally available. The beta label is gone: hosted comments with a first-party ML spam filter, no-account commenting, threaded replies, reactions, and a full moderation dashboard are all production-ready.
    • The Hobby tier is a permanent free plan for your first site — 10,000 page views and 1,000 comments per month, no credit card, not a trial.
    • Lifetime-free guarantee for early adopters: anyone who joined before launch keeps the Hobby tier free for life on every site they had at launch, even if Hobby limits change later. No rug-pulls.
    • Paid plans (Starter $5/mo, Pro $19/mo, Business $79/mo) are available when you outgrow Hobby, billed through Stripe with soft usage limits and warning emails before anything is enforced.
  39. Spoiler tags + clearer formatting in the comment composer

    • Spoilers: type `||your spoiler||` in any comment — readers see a masked block they can click (or focus and press Enter or Space) to reveal, Escape to re-mask. Keyboard-focusable with `aria-label` state announcements; aligned with WCAG 2.1 AA.
    • Composer toolbar reordered to make formatting obvious: Bold · Italic · Spoiler · divider · Emoji · Image. Each format button shows its keyboard shortcut and the matching markdown in the tooltip.
    • New empty-state hint inside the composer (`Format: **bold** · _italic_ · ||spoiler||`) that disappears once you start typing — zero noise, full discoverability.
    • Existing **bold** and _italic_ syntax keeps working unchanged; this ships only as additions and a visual refresh of the toolbar.
  40. Accessibility, keyboard speed, and zero-CLS loading

    • Embed widget now ships visible focus rings on buttons, inputs, and the compose editor, ARIA labels on the compose toolbar, image-remove, and lightbox-close buttons, a focus-trapped image lightbox, and broad prefers-reduced-motion coverage across animated affordances — moving the widget closer to WCAG 2.1 AA.
    • Moderation queue: keyboard shortcut hints (A approve, R reject, D delete, I open profile) now appear on the focused row, so power-user moves are discoverable without leaving the page.
    • Moderation queue: recent searches stay one click away (session-scoped), bulk actions report live progress, and a fresh-load timestamp tells you exactly how stale the view is.
    • Comment list now loads with skeleton placeholders instead of a spinner — eliminates the layout shift readers used to see on slow networks.
    • "Be the first to comment" empty state on fresh threads invites readers in instead of showing a silent gap.
    • Faster notification cleanup: "Mark all read" and "Clear all" run with bounded concurrency server-side instead of one sequential update per item.
  41. SEO internal links across docs and blog

    • Added "Further reading" links from /docs into related blog posts.
    • New per-post SEO update script for bulk-tuning blog meta titles and descriptions.
    • Tightened blog post fallback titles to match the H1 (no more drift between rendered H1 and meta).
  42. AI spam-prevention spotlight on the homepage

    • New "Spam doesn't stand a chance" section showing a live moderation queue mockup.
    • Surfaced inline scoring and the Siftfy classifier brand in the moderation mockup.
  43. Siftfy ML spam classifier replaces heuristic filter

    • New comments are scored by a trained ML classifier instead of keyword heuristics when spam filtering is enabled.
    • Borderline scores route to the moderation queue; high-confidence spam is filtered out of the public thread.
    • Spam filtering can be toggled per site from the Site Settings panel.
  44. Admin recent-activity panel

    • Dashboard home now shows a unified recent-activity feed across all sites you own.
    • Notification bell with unread count.
  45. Bulk moderation actions in the queue

    • Multi-select comments in the moderation queue and approve / reject / mark-spam in one click.
    • Keyboard shortcuts (a / r / s / d) for power moderators.
  46. Blog launched

    • /blog goes live with launch announcement, competitor breakdown, and a "drop-in comments anywhere" guide.
    • Blog runs on a separate S3+CloudFront pipeline so it can ship independently of the dashboard.