Vitalpax Inc.
Quotation Tool CRM
Development Updates
Servings-per-container now flows from Sales straight into the R&D Lab, the Supplement Facts preview gets macro toggles plus full Child Supplement support, component search returns sharper results, and stickpacks land across the Sample Spec and Master Product Specification - capped by a three-part security hardening push closing XSS, SQL injection, and email-header injection risks.
June 24 - 29, 2026
Section
New Features &
Enhancements
Servings per Qty flowing from Sales into the Lab, a clearer Supplement Facts preview with macro toggles and Child Supplement support, smarter component search, and full stickpacks support across the Sample Spec and Master Product Specification.
Major Enhancement
Servings per Container, Sales to Lab
- Per-Tier Entry -- Sales can now enter Servings per Qty on each quantity tier in the product modal - Tier A required, Tiers B-D optional.
- Auto-Fills the Lab -- When the quote moves to R&D, those values pre-fill the Lab Settings without overwriting anything R&D has already edited.
- Shown in Summaries -- The Sales tab and Edit Product summaries now surface a Servings per Qty column for at-a-glance review.
- Two-Way Sync -- Changing Containers per Work Order in R&D updates the matching Pricing rows, unless that row was already edited or deleted.
Feature Update
Cleaner Supplement Facts Preview
- Macros Toggle -- Macro rows (Calories, Fat, Carbs, Protein) are hidden by default for supplements and toggle on from the dialog footer; foods still show them by default.
- Single %DV Column -- Only the 4+ years %DV column shows unless the product is flagged as a Child Supplement, in both the preview and the generated PDF.
- Aggregated Claims -- Multiple source rows for the same nutrient - such as Magnesium Citrate and Magnesium Oxide - now roll up into a single label-claim line.
Feature Update
Child Supplement Support
- New Service Type -- A Child Supplement service type can now be selected in the Sales tab Service Types alongside Bulk Products, Existing Formula, and the rest.
- Age-Banded %DV -- Flagging a product as a Child Supplement expands the preview and PDF to show %DV columns for ages 0-1, 1-3, 4+, and Pregnant or Lactating.
- Accurate Labels -- Children's products now generate the correct multi-column Daily Value breakdown required for their audience.
Feature Update
Sharper Component Search
- Most-Relevant First -- Component search now returns the most relevant results for each slot - bottle, lid, neckband, scoop, and more - when first opened or auto-prefilled.
- Broadens On Typing -- The result pool widens as soon as the user actively types a search, so nothing relevant is hidden once they start looking.
- Consistent Across Tabs -- The R&D Lab and Sales/Pricing tabs now produce identical results for the same query.
Feature Update
Stickpacks: Sample Spec & Lab Settings
- Full Stickpacks Support -- The Sample Product Specifications sheet and the Lab Settings dialog now fully support the stickpacks format.
- Solvent & Flavor -- The Sample Spec modal shows Recommended Solvent, displays Flavor as a read-only value from lab settings, and omits the Aroma row.
- Free-Text Solvent Qty -- Edit Lab Settings uses a free-text Recommended Solvent Qty input, which the stickpacks formulation header also displays.
Feature Update
Stickpacks on the Master Product Spec
- Powder Color & Flavor -- The Master Product Specification now correctly shows Powder Color and Flavor rows for stickpacks alongside Avg Weight/Fill and Weight/Fill Variation.
- Instant Reflection -- Edits made in the Lab Settings dialog now appear in the MPS modal immediately, with no page refresh required.
Section
Bug Fixes
The SP314425 film seal-template component is back in the product components list for film-format products.
Bug Fix
Missing Film Component Restored
- Back in the List -- The SP314425 film seal-template component was missing from the product components list and could not be picked.
- Selectable Again -- It can now be selected for film-format products, complete with its linked vendor pricing.
Section
Security Hardening
Three patches close real attack paths: stored cross-site scripting in Ingredient Request notes, SQL injection in the NIH CSV uploader, and email-header injection in the Send Quote dialog.
Security Patch
Cross-Site Scripting Fix in Notes
- The Risk -- Hidden code pasted into Ingredient Request notes could silently run in another user's browser the moment they opened the request - potentially stealing their session.
- The Fix -- Notes are now read in a way that ignores any code inside, so they render as plain, harmless text.
- More To Come -- This is the first form to get the treatment; other free-text areas across the app are being reviewed for the same protection in upcoming updates.
Security Patch
SQL Injection Hardening: NIH Uploader
- Allow-List Guard -- The NIH CSV uploader now clears only an explicit list of approved internal tables before importing data.
- Defense In Depth -- This internal safety net stops any future change to the upload code from accidentally or maliciously targeting an unintended table.
Security Patch
Email Header Injection Fix: Send Quote
- Validated Fields -- The Compose Quote Email form now validates the To, CC, and Subject fields before sending.
- Capped & Cleaned -- Invalid addresses are rejected, the CC list is capped at 10 recipients, and subjects containing hidden line breaks are blocked.
- No Hidden Recipients -- This prevents attempts to inject hidden BCC recipients or other email headers through the Send Quote dialog.
Summary
What We Shipped
5
Features & Enhancements
1
Bug Fix
3
Security Patches
Servings per Qty now flows from Sales into the R&D Lab, the Supplement Facts preview gained macro toggles and full Child Supplement support, component search returns sharper and more consistent results, and stickpacks landed across the Sample Spec and Master Product Specification - while a three-part security push closed cross-site scripting, SQL injection, and email-header injection risks and one fix restored the missing film seal-template component.