---
title: "Financier changelog"
description: "Changes to Financier, newest first, including security fixes."
canonical: https://financier.sh/changelog
updated: 2026-10-05
---

# Financier changelog

Changes to Financier, newest first, including security fixes.

## v2026.10.3, October 5, 2026

| | |
| --- | --- |
| Changed | Cashflow is Income by source, Spending by category, and income against spending by month. The cash projection is removed. |
| Changed | Trust page restated as a Trust Center: overview, data protection, infrastructure, application security, AI use, subprocessors, incident response and disclosure. |

## v2026.10.2, October 5, 2026

| | |
| --- | --- |
| Security | Next.js upgraded to 16.3.8, fixing remote code execution in social image generation (GHSA-vcvr-r3jv-pc5j). |
| Security | Dependencies are checked for known high and critical vulnerabilities on every change. |
| Added | Changelog page, including security fixes. |
| Changed | Security page renamed Trust and restated. |
| Added | Moving a charge can cover the merchant's charges of a similar amount, now and in future. |

## v2026.10.1, October 5, 2026

| | |
| --- | --- |
| Security | Plaid errors no longer carry Financier's Plaid secret or a bank access token into server logs. |
| Security | A connection already removed at Plaid no longer blocks disconnecting it or deleting the account. |
| Security | After sign-in, redirects are limited to Financier's own pages. |
| Security | HTTPS is enforced (HSTS); a content security policy and framing protection are in place. |
| Security | Password accounts confirm their email before signing in. Google sign-in joins only accounts with a confirmed email. |
| Security | Outbound webhooks connect only to an address checked against private and reserved ranges. |
| Security | Plaid webhook signing keys are trusted only until they expire; lookups of unknown keys are limited. |
| Security | Writes started by other sites are refused. Sign-in rate limits always apply. |
| Added | Two-step sign-in with an authenticator app, with single-use backup codes. |
| Added | Password reset by email. |
| Added | Wealth: net worth by account, and its trend. |
| Added | Several banks can be connected in one Plaid session. |
| Changed | Overview is now Today, with this month compared to last month at the same point. |
| Changed | Plan is now Cashflow, by month range, opening into categories, merchants and transactions. |
| Changed | Income settings moved to Settings, Income. |
| Changed | Onboarding is one step before the plan: add accounts. |
| Changed | Available today shows the amount over when spending passes the month's budget. |
