Hi everyone,

I’m David – CEO of Cmsmart Ecommerce, Netbase JSC.

This note covers every release since the 2.15 note: 2.15.1 (17 Sep 2026), 2.16.0 (24 Sep), 2.16.1 (28 Sep) and 2.17.0 (2 Oct). The theme is one thing: the print file your shop receives is the file your customer approved. The print-ready PDF now exists when the customer clicks Process, matches the size they chose, is renewed when they reorder or edit, and approved artwork can no longer be overwritten. Image import is also much stricter about what it accepts. If you are on 2.15.0 or older, read the security section first.

Applies to Cmsmart Product Designer (NBDesigner) 2.17.0 — updated October 2026. Covers 2.15.1, 2.16.0, 2.16.1 and 2.17.0. Earlier changes are in the 2.15 release note.

In short

  • Print files: PDF rendered on Process (2.16.0), attached to the admin order email, matching custom sizes (2.17.0), a fresh file on reorder, and a print-ready status with Regenerate on the order screen.
  • Approved artwork is locked on the server (2.17.0); editing a design after ordering queues a new print file.
  • Security (2.16.1): remote image import stores only real JPG, PNG or GIF files; upload-folder script blocking applies on every site. Stores older than 2.15.0 should update.
  • Tablets and phones: rotating a tablet or resizing the window no longer rescales the design (2.17.0), and iPhone viewport fixes (2.15.1).

Existing users: what do I need to do?

Update like any other plugin, after a backup. Activating 2.17.0 adds two small tables for the new connector foundation (see below); the changelog lists no license or domain change. Three things are worth checking afterwards:

  1. In Cmsmart › Settings › Output › Synchronize, switch on Auto export design to PDF if you want the PDF made on Process.
  2. In Cmsmart › Settings › General › Notifications, add Print-ready PDF under Attach custom designs type to receive it by email.
  3. Check Render print PDFs in the cloud (General › Tools, now visible, on by default). Choose No, render on this server if you prefer to render on your own server.
Cmsmart Settings Output tab Synchronize section: Auto export design to PDF, order status, Also save print-ready PDFs in the pdfs folder and file sync destinations
Output › Synchronize in 2.17.0: automatic PDF export, the new pdfs-folder copy option and file sync destinations.

Running Nginx? It ignores .htaccess, so the script-blocking rules the plugin writes into its upload folders do nothing there. Add an equivalent server rule.

How does the print-ready PDF work now?

It is produced when the customer clicks Process, and you can see its state on the order. Before 2.16.0, the design was exported only when the order reached the selected status, so the Files page kept showing a preview image until someone made the PDF by hand. Now Process queues a background render right after the design is saved (checkout does not wait), and the order status still re-checks and re-renders if the PDF is missing, invalid or out of date.

NBDesigner editor with the Process button at the top right
The Process button in the modern editor: clicking it queues the print-ready PDF.

The file matches what the customer designed (2.17.0)

  • Custom sizes. When the buyer chose their own width and height, the automatic render used the product template’s size and the template background, so the file looked like the mockup. The cloud renderer, the server renderer, the preview and Create PDF now read the same page geometry, including the custom size.
  • Reorders start fresh. A reorder used to copy the old order’s PDFs and certificate into the new design, so no new render ran. The old outputs are now left behind and, with automatic export on, a render is queued.
  • Older PDFs are rendered again. PDFs made by 2.16.x are re-rendered when the order reaches the export status again, when an admin downloads from the order screen or uses Regenerate, because the certificate now carries the output version.
  • Create PDF with the default settings makes the print-ready PDF, using the same renderer as automatic export. Changing paper size, margins, bleed lines, background or source still builds a custom layout, which is not the print-ready file.
  • Print-ready status on the order artwork screen: Ready (when and by which renderer), Rendering, Failed or Not rendered, with the files and a Regenerate print-ready PDF button.
Cmsmart order detail with production timeline, design file and AI Preflight panel (test order)
Order detail in 2.17.0 on a test order: production timeline, design file and AI Preflight.

The artwork reaches you by email (2.16.0)

Print-ready PDF is a file type next to PNG and SVG for the order notification. Only a PDF the plugin has certified for the current design is attached. If it is still rendering when the notification goes out, the email is sent on time and a second email delivers the artwork when it is certified. Files above the 15 MB attachment budget are named in the email and left in the order. A render that fails after three attempts sends one alert naming the order, design and reason; the Print-ready artwork emails setting switches both messages off.

Optional: copy PDFs where your own code expects them

New in 2.17.0, Output › Also save print-ready PDFs in the pdfs folder (off by default) copies every print-ready PDF into each design’s pdfs folder under the names Create PDF uses. Turn it on only if your own code or another plugin reads that folder. Developers can use the filter nbd_pdf_legacy_mirror_enabled.

Can approved artwork still be changed?

No, not once it is approved (2.17.0). Saving over a design whose order item is approved is refused with a clear message, whatever link or open designer tab the save comes from; before, only the Edit design button was hidden. Shops can widen the lock with the filter nbd_ordered_design_edit_locked. When a customer does edit a design after ordering (and it is not locked), the order is flagged as changed, a declined proof returns to pending review, an order note is added, and a print-ready PDF is queued if automatic export is on.

Is my store exposed to the image import problem?

Only if you run a version before 2.15.0. Those versions allowed an unauthenticated visitor to upload an executable file through the image import. 2.16.1 goes further: importing an image by URL checks the downloaded bytes and saves the file with the extension of the real image type, refusing HTML, scripts, SVG or an image with code appended. Downloads are capped at 10 MB and follow at most two redirects; Google Drive import rejects malformed file IDs, times out after 30 seconds and never follows redirects. Script blocking is now applied on every request to the design, upload and temporary folders, including folders that already had an .htaccess, and it catches double extensions like name.php.jpg.

NBDesigner photos panel with Upload, Image url, Facebook, Instagram, Dropbox, Webcam, Pixabay, Unsplash, Pexels and Freepik
The Photos panel: image import by URL and other sources is what 2.16.1 hardens.

What changed for tablets, phones and uploads?

  • Rotating a tablet or resizing the window no longer rescales the design (2.17.0). Since 2.15.1 a width change rebuilt the stage but left the artwork at its old pixel size, so the design grew or shrank against the design area and was saved that way. It now keeps its size and position.
  • Artwork no longer rescales after iPhone address-bar or keyboard changes (2.15.1), and a design saved on a phone reopens at the right size. Stored viewports are validated, and every notch-era iPhone gets the right allowance for browser chrome.
  • An uploaded PDF is placed at its real size (2.15.1), previewed at up to 300 DPI; the AI upscale suggestion skips PDF layers.
  • Local cliparts show again on sites whose upload URL is root-relative, and deleting a background works again on PHP 8 (2.15.1).
  • A missing design folder no longer drops a design from an order silently (2.15.1), and PDF download failures now explain the cause.
  • Smaller 2.17.0 fixes: designer scripts and styles load with a version so browsers and CDNs pick up updates; the Customer Design box works on the HPOS order screen; checkout shows the quantity once for items with both a design and print options; the admin approval email works in translated stores; no PHP 8.2+ deprecation from PDF exports.

What is the CMSmart Connector foundation?

2.17.0 adds the groundwork (site enrollment, signed requests, a durable outbox and command store) for connecting your site to the CMSmart Dashboard. It is off by default: nothing is sent and nothing is scheduled until the nbdesigner_connector_enabled option is set to yes. Activation adds two connector tables. It is not something you need to act on today.

What do developers get?

Actions nbd_print_pdf_ready and nbd_print_pdf_failed; filters nbd_pdf_email_attach_types (admin new_order only by default, so buyers are never sent print artwork), nbd_pdf_email_recipients, nbd_pdf_email_max_attachment_bytes, nbd_ordered_design_edit_locked and nbd_pdf_legacy_mirror_enabled.

Full changelog

2.17.0 – 2 Oct 2026

New

  • CMSmart Connector v1 foundation (off by default).
  • Create PDF with default settings makes the print-ready PDF.
  • Print-ready status and Regenerate button on the order artwork screen.
  • Output › Also save print-ready PDFs in the pdfs folder (off by default).
  • General › Render print PDFs in the cloud is now visible (on by default).
  • The render certificate records renderer, fallback reason and page size per side.

Fixes

  • Rotating a tablet or resizing the window no longer rescales the design.
  • Automatic print PDFs match Create PDF for custom-size products; the cloud renderer leaves out the overlay for layout c.
  • Reordering starts a fresh print file; PDFs made by 2.16.x are rendered again.
  • Approved artwork is locked on the server; editing after ordering queues a new print file.
  • Versioned designer assets; HPOS Customer Design box; quantity shown once at checkout; markup, rejection notice and status fixes; translated approval email; PHP 8.2+ deprecation.

2.16.1 – 28 Sep 2026

Security

  • Remote image import stores only real images, capped at 10 MB with at most two redirects; Google Drive import hardened.
  • Upload-folder script blocking applied on every request, including folders with an existing .htaccess; catches double extensions.

2.16.0 – 24 Sep 2026

New

  • Print-ready PDF attach type; second email when the artwork was not ready; alert on a failed render and the Print-ready artwork emails setting; developer hooks.

Improvements

  • Auto export design to PDF covers both Process and the order-status fallback; order-detail downloads reuse the certified PDF.

Fixes

  • PDF produced on Process; renders verified, retried and marked Failed if they give up; no duplicate renders.

2.15.1 – 17 Sep 2026

Fixes

  • Viewport and rescale fixes for phones and saved designs; PDF upload size and preview; AI upscale on PDF layers; local cliparts; background deletion; missing design folder; PDF download diagnostics.

Frequently asked questions

Which version should I be on?

2.17.0 or later. Versions before 2.15.0 allowed an unauthenticated executable upload through image import.

Do customers get the print-ready PDF by email?

No. By default only the admin new-order notification can carry print files, so buyers are never sent print artwork.

Is the PDF created when the order completes or when the customer clicks Process?

When the customer clicks Process (2.16.0). The order status you pick still re-checks and re-renders if the PDF is missing or out of date.

Can I render PDFs on my own server?

Yes. Set General › Tools › Render print PDFs in the cloud to “No, render on this server”. If a cloud render fails, the server renders instead (this needs the bundled PHP TCPDF library).

How to get it

Update from your Cmsmart Dashboard or start the free 30-day trial from the Products page. See the WooCommerce product designer plugin page, the live demo (now on 2.17.0), the user guides, and the 2.15 release note. Need print-shop customisation? Request a quote.

— David, CEO of Cmsmart Ecommerce

David Nguyen

David Nguyen

eCommerce consultant
Member since Jan 2020
310 Posts
211,439 Views
0 Helpful
David Nguyen
Founder & CEO, Cmsmart Ecommerce (a division of Netbase JSC)
With over 20 years of experience in business strategy and ecommerce technology, David Nguyen has empowered hundreds of online retailers around the world to scale smarter and faster. As the visionary behind Cmsmart, he has driven the development of personalization solutions and product-customization tools that deepen customer engagement and boost average order values. His commitment to creativity, practical strategy and results-driven outcomes has earned Cmsmart a reputation as a trusted partner for small, medium and enterprise-level ecommerce brands.

Contact Me via WhatsApp: https://wa.me/84937869689

Email: [email protected]

Let’s talk about how your ecommerce store can grow.
If you're ready to transform your store with tailored solutions that drive engagement and revenue, send me a message on WhatsApp or email today — and our team will connect with you right away.