Skip to main content

Changelog

What's new in CompleteStatus

New features, improvements and fixes we've shipped, newest first.

RSS feed
Improved

TLS configuration grading updated

TLS configuration monitors and the free TLS scanner can now detect hosts that still accept TLS 1.0 or 1.1, or NULL and anonymous cipher suites. Before, those probes failed on our side, so such hosts looked better than they are. A host that still accepts them now grades C or D; for example, a site behind Cloudflare with its default minimum TLS version of 1.0.

Scoring for legacy protocols now matches the rubric published on the TLS scanner page.

The "Every week" check interval has been retired. Monitors that were set to weekly now run once a day.

Fixed

API and transaction assertions compare values by type

JSONPath assertions using equals or not equals now compare by JSON type. true, false and null match JSON booleans and null, and JSON text such as [] matches arrays and objects by structure. Before, $.degraded equals false passed even when the API returned true, and $.items not equals [] passed on an empty list.

There is also a new does not contain operator. For Body contains, not equals now means "does not contain", and a JSONPath assertion against a response that is not valid JSON (an HTML page, an empty or cut-off body) now fails whatever its operator.

Some monitors may change state after this update, because they now evaluate as written. Review monitors that use equals/not equals with true, false, null or [], that pair Body contains with not equals, or that run JSONPath assertions against responses that are not JSON.

Keyword, API, transaction and content-change monitors on pages in other languages or older character sets, which sometimes failed with "Check aborted unexpectedly.", now check normally. Characters that can't be read are shown as �.

Improved

Reputation checks now use Google Web Risk

Reputation monitors and the free Website Security Score now check URLs against Google's threat lists through the Google Web Risk API, Google's service for commercial use. They used the Safe Browsing API before. The threat types are the same: malware, social engineering (phishing) and unwanted software.

Your URLs now stay on our servers. We keep a copy of Google's lists, check it for updates every 30 minutes, and check URLs against it ourselves. We only contact Google to confirm a possible match, and then we send a short piece of the URL's hash, not the URL.

The monitor setting is now called Check Google Web Risk. Your existing setting is kept, and so are your earlier results; those are still labelled Google Safe Browsing. When the lookup can't run, for example before the lists have finished downloading or if they have fallen out of date, the card shows Not checked with the reason and nothing is flagged.

Improved

Plan changes now take effect straight away, and nothing is deleted

When an organization moves to a smaller plan, or a paid plan ends, whatever the new plan doesn't include is now paused or suspended as soon as the change goes through. Nothing is deleted, and most of it comes back on its own when you upgrade again.

  • Team members beyond the plan's seats (the most recently added first, never an owner), and Client members on a plan without the client role, are suspended. They see a page explaining why, and API keys they created stop working. Their access comes back automatically once the plan has a seat for them.
  • PagerDuty, Opsgenie, GitHub, GitLab, Jira and Linear channels stop receiving new alerts on plans without them. The channels are kept, and a recovery still resolves an incident or ticket opened before the change. They deliver again as soon as your plan includes them.
  • Transaction monitors are paused on plans without them, monitors over the plan's limit are paused newest first, and monitoring regions are cut to what the plan allows.

The organization's owners get one email listing exactly what changed and what an upgrade brings back, and owners and admins see a banner while anything is held back. Region choices, check intervals and custom domains are not restored automatically after an upgrade, so set those again. See Moving to a smaller plan.

Improved

Each plan now shows its own length of history

How far back you can see your monitoring history now follows your plan: 14 days on Free, 1 year on Pro, 2 years on Business and Agency, and 3 years on Enterprise. That applies everywhere history appears: status page uptime bars, the status badge and incident history, LiveStatus walls, the monitor page, the dashboard, the security score trend, SLA reports and the API's uptime and check results.

  • Nothing is deleted. Your history stays stored whatever your plan, and it is shown again as soon as you move to a plan that covers it.
  • On Free, a status page shows 14 daily bars instead of 90, and the dashboard's uptime tile covers the last 14 days.
  • Reports start no earlier than the first day your plan shows, and the preview tells you when a report was cut short.
  • The API cuts a longer days to your plan's window and says so in window.history_days.

Your incident list is not affected. See What your plan allows.

New

Ping (ICMP) monitors

You can now monitor a host or IP address with ping. Each check sends 1 to 5 packets, records packet loss and round-trip times, and you choose how much packet loss counts as down.

Ping suits servers and network equipment that don't run a web server. Some networks block ICMP, so the form reminds you to check that first. The UptimeRobot, Pingdom and CSV importers now bring ping monitors across instead of skipping them.

Improved

Faster public pages and status pages

Public pages no longer load a large JavaScript bundle. The homepage now loads about 165 KB of scripts and styles instead of about 1.19 MB, and public status pages dropped from about 1.18 MB to 155 KB.

The dashboard is lighter too, and static files are now cached by your browser for longer, so repeat visits load faster.

Fixed

Content-change monitors now alert reliably

Content-change monitors detected changes but never sent an alert for them. A detected change now counts on its own, without waiting for a second check, so you are notified when the page changes.

Connection errors on these monitors still need the usual confirmation before they alert.

Improved

Steadier outage and recovery alerts

A monitor now needs two good checks in a row before it is marked as recovered, matching the two failed checks it takes to mark it down. A flapping site no longer sends a down and up pair on every blip.

After the first failed or first good check we re-check within about 60 seconds, so even monitors that normally run once a day confirm an outage or recovery in around a minute. Repeat down alerts have a 5-minute cooldown by default, and a recovery notice always goes to the channels that received the matching down alert.

Fixed

More private password resets, and account linking for Google sign-in

The forgot-password form now gives the same answer whether or not an email address has an account, so it can't be used to find out who uses CompleteStatus.

We've also built account linking for Google sign-in, which isn't available yet. Once the "Continue with Google" button appears on the sign-in page, an account you created with a password can be linked by signing in with your password once; after that Google signs you in. Until then, sign in with your email and password as usual.

Improved

Latency alerts only for real slowdowns

Slow-response alerts were firing too often, sometimes every hour on the same slow day. A latency alert now needs a meaningful slowdown: response times at least 1.5 times the monitor's normal level and at least 250 ms slower, measured over enough checks to be reliable.

Each monitor sends at most one latency alert per 24 hours, and each channel receives at most three a day across all monitors. Down, recovery, certificate and domain alerts are not affected.

New

Personal notification preferences and quiet hours

Each person can now choose which email notifications they receive under Settings > Notifications, and set quiet hours. Everything stays on until you turn it off.

Quiet hours never hold back an outage alert. Preferences also only apply to email sent to your own address, so a shared inbox, a Slack channel or a PagerDuty integration can't be silenced by one person's settings.

New

Single sign-on and security policies for Enterprise

Enterprise organizations can connect their identity provider over OpenID Connect (for example Microsoft Entra ID, Okta, Google or Auth0) and let members sign in with single sign-on.

Owners can also require two-factor authentication for every member, allow SSO-only sign-in, and set session and idle timeouts for the organization.

New

Domain-expiry alerts, data export and self-serve deletion

Domain monitors can now alert you when a domain registration is getting close to expiry, by email or on any of your other alert channels.

You can also download an export of your organization's data at any time (secrets are redacted), and owners can delete an account or organization themselves after confirming their password.

New

Team members and invitations

Owners and admins can now invite teammates from Settings > Team, assign roles and remove members. Each invitation is single-use and expires after 14 days, and a copyable invite link sits next to every pending invitation.

The number of seats depends on your plan. A pending invitation holds a seat until it is accepted or revoked.

Fixed

Certificate-expiry and security-grade alerts now arrive

Alert rules for "certificate expiring soon" and "security grade dropped" could be switched on, but those notifications were not being sent. They are now delivered to your alert channels like any other alert.

These warnings do not open incidents, so an upcoming certificate renewal never counts as downtime or affects your uptime figures and status pages.

New

Add many monitors at once from a list of URLs

You can now paste a list of URLs, one per line, and create an uptime monitor for each. It copes with lists copied from spreadsheets or notes: https:// is assumed, bullets and trailing commas are ignored, and "Name, URL" lines work in either order.

Nothing is dropped silently. Lines that can't be read appear in the preview with the reason, and duplicates are flagged before anything is created. Look for "Bulk add URLs" on the monitors list.

New

Custom domains for status pages

On paid plans you can serve a status page from your own domain, such as status.example.com. Point a CNAME record at us, or add a TXT record if your DNS setup can't use a CNAME there, and the page editor shows when the domain is verified.

We re-check the DNS every hour. If a verified domain's record breaks, the page keeps serving for a grace period, so a DNS mistake doesn't take your status page offline straight away.

Improved

Status pages group repeat incidents

When the same monitor fails for the same reason several times in one day, your public status page now shows it as a single line, for example "recurred 4× (first 09:12, last 11:40)", instead of a long list of near-identical rows.

The visible timeline shows the 10 most recent entries, and older ones fold into an expandable section. Single incidents look exactly as before.

New

Account & security page with two-factor authentication

There is now an Account & security page in the user menu. You can change your name, email address and password there, and turn on two-factor authentication with any authenticator app.

When 2FA is on you get a set of recovery codes, which you can view or regenerate at any time. Changing your email address asks you to verify the new one.