Tag: plugins

  • Developers Raise Concerns About WordPress.com Plugin Listings Outranking WordPress.org on Google Search

    WordPress core developer John Blackbourn sparked a heated discussion yesterday when he posted an image of his WordPress User Switching plugin ranking higher for the WordPress.com listing than the page on WordPress.org.

    Blackbourn later apologized for the inflammatory wording of the original post, but maintains that .com plugin listings being displayed higher in search results is not healthy for the open source project.

    “This was a frustrated 2AM tweet so I could have worded it better, but the point still stands,” he said. “The plugin pages on dotcom are little more than marketing landing pages for the dotcom service and they’re strongly competing with the canonical dotorg pages. That’s not healthy.”

    Several others commented about having similar experiences when searching for plugins, finding that the WordPress.com often ranks higher, although many others still see WordPress.org pages ranked highest.

    Blackbourn said his chief concern “is the process that introduced the directory clone on .com either disregarded its potential impact on .org in favor of inbounds or never considered it in the first place – both very concerning given the ranking power of .com.”

    The tweet highlighted the frustration some members of the open source community feel due to the perennial branding confusion between WordPress.com and WordPress.org. Nothing short of renaming WordPress.com will eliminate the longstanding confusion, but this is unlikely as Automattic benefits from tightly coupling its products to WordPress’ name recognition.

    “Duplicate content confuses the human + search engines,” SEO consultant Rebecca Gill said. “Search engines won’t like it, nor will humans trying to find solutions to their problems. There is already enough confusion w/ .org + .com for non-tech folks. This amplifies it. Noindex .com content or canonical it to .org.”

    Participants in the discussion maintain that the duplication of the open source project’s plugin directory “creates ambiguity and confusion” but WordPress co-creator and Automattic CEO Matt Mullenweg contends it also gives plugin authors greater distribution.

    “It’s providing distribution to the plugin authors, literally millions and millions of installs,” Mullenweg said. He elaborated on how the cloned plugin directory is integrated with Calypso, WordPress.com’s admin interface:

    .com has its own plugin directory which includes the .org one, it provides more installs and distribution to the plugin authors, which helps their usage and for commercial ones gets them more sales. The plugins are not altered. .com takes no cut for the distribution.

    When participants in the discussion suggested that other hosts doing the same thing would create a wild west situation for plugin rankings, Mullenweg said he would not mind if the plugins were “duplicated and distributed by every host and site on the planet,” as they are all licensed under the GPL.

    Outrage against distributing WordPress.org plugins in this fashion was not universal in the discussion. A few commenters support this strategy and see it as beneficial for the long-term health of the open source project.

    “I’m all for it to be honest,” WordPress developer Cristian Raiber said. “Anyone could scrape those pages but not everyone gives back to WordPress and makes sure it’s here to stay for the next decades. Controversial, I know. But I prefer we build together instead of alone.

    “I fail to see how this is not an advantage to anyone who hosts their plugins (for FREE) on w[dot]org ?” Raiber continued in a separate response. “Is it about being outranked in Google’s SERPs for brand kws? Why has this generated so much outcry when the intent is clearly beneficial?

    “This FINALLY solves a friction point for potential buyers. Streamlined plugin installation and usage vs ‘here’s a list of 55 steps you have to take to install my plugin.’ Users want options, different uses cases and all. I want wp.com to make money so they keep growing this product.”

    XWP Director of Engineering Francesco Marano suggested that WordPress.com has benefitted from the branding and reputation of .org, which is built by volunteers. She also proposed that Automattic “has the resources to do a whole rebranding which would ultimately benefit both projects.”

    Mullenweg responded to these comments, defending WordPress.com’s efforts in fending off early WordPress competitors and cited Automattic’s preeminence in contributing back to core, despite taking in less revenue than some larger companies making money from the software:

    Since its foundation, .org has benefitted from the branding and reputation of having a robust SaaS version available from .com, including a free version, something basically no other host does. Over 200M people have used it, and countless started on .com and then migrated to another host. The shared branding made it very difficult for services like Typepad to compete. You want to see what WP would look like without it? Go to Joomla.

    .com has also been the source of countless performance improvements, we deploy pre-release versions of core to millions of sites to find bugs and do testing, making WP releases way more stable for regular users and hosts. No company contributes more, even though many make more from WP than .com’s revenue. It would have been way easier to fork the software, not merge MU. Most hosts (and many community members) bad-mouth .com while not contributing a fraction back to core. Hosts spend tens of millions a year on ads against .com. I get attacked constantly.

    In 2010, when the WordPress Foundation was created, Automattic transferred the WordPress trademarks to the Foundation, after having been the temporary custodian of the trademarks until that time. As part of the transfer, the Foundation granted Mullenweg use of the WordPress trademark for WordPress.com.

    This trademark was deliberately secured, and the company does not appear to be open to renaming the platform. This doesn’t mean WordPress.com can’t do anything to mitigate the confusion that scraping the WordPress.org plugin directory creates. Participants in the discussion suggested that WordPress.com forego indexing the pages they created for plugins that developers submitted to the open source project.

    “You can control SEO by telling search engines to not index those pages of open source software developed for .org on the .com domain,” WordPress plugin developer Marco Almeida said.

    “I have 20 free plugins on the repository and I don’t see how my plugins will benefit if we open this pandora box and normalize cloning these pages and diluting the WordPress.org importance on search engines.”

    Developers who are just now discovering their WordPress.org plugins cloned to WordPress.com listings are also wanting to know how many of their installs come from WordPress.com so they can better understand their user bases. Mullenweg suggested developers who want a different listing for WordPress.com users can sign up for the .com marketplace.

    Tensions remained high as the heated discussion continued throughout the day and into the evening with criticism flowing across X (Twitter), Post Status Slack, and other social channels, as many developers learned for the first time that their plugin listings have been cloned on WordPress.com. As long as a commercial entity shares the open source project’s branding, these types of clashes and friction will continue popping up.

    “Personally, I can’t help but empathize with plugin authors that chose to support OSS and find the directory cloned in a commercial service, albeit free, with no access to stats,” Francesca Marano said. “As I mentioned before, the main issue is the confusion around the two projects.”

    Go to source

  • WordPress.org Plugin Developers Renew Demands for Better Plugin Metrics

    It has be nearly one year since WordPress silently turned off active install growth data for plugins hosted in the official plugin repository, a key metric that many developers rely on for accurate tracking and product decision-making. “Insufficient data obfuscation” was cited as the reason for the charts’ removal, but this opaque decision landed without any communication from those who had made the call in a private discussion.

    In a ticket originally titled “Bring back the active install growth chart,” RebelCode CEO Mark Zahra made the opening plea for thousands of plugin developers who were asking for the return of this data. From those who simply host hobby plugins and enjoy the thrill of watching people use software they made to business owners who need this data to make critical decisions, the overwhelming consensus was that this data is valuable and should be available to those who are contributing to WordPress through plugins.

    In an appearance on the WPwatercooler podcast last year, Audrey Capital-sponsored meta contributor Samuel “Otto” Wood confirmed the decision was made through private channels via Slack DMs in a discussion initiated by Matt Mullenweg. He also revealed that the active install growth chart was removed because it was giving inaccurate data and that the data one could derive from it was inaccurate:

    I read through all that discussion and we worked, they worked on it for a long, Scott and several people tried various things before removing it. They adjusted the values, they adjusted numbers. They, they went through a ridiculous amount of iteration and in the end, none of it worked. People were still using it even though it was giving them basically garbage. So finally removing it was the only thing to do. We did have a plan for replacing it. We just didn’t have a plan for replacing it immediately. Nevertheless, giving them active install count numbers that are wrong is more harmful, we felt, to both users and developers interests than simply not giving them at all. 

    Wood offered an explanation on the podcast that should have been delivered weeks earlier by those involved in the discussion on official channels. Despite the earlier data being flawed and “insufficiently obfuscated,” developers still want access to the raw data, not interpretations of that data.

    These are the posts that track the history and development of developer’s pleas to reinstate access to the data:

    During the height of this discussion, developers made many suggestions for different data points that would be meaningful for tracking their efforts, and Matt Mullenweg responded that he was amenable to showing more stats to plugin authors about their plugins. No progress on this effort has been reported since then.

     StellarWP Product Marketing Director Taylor Waldon has reopened this discussion nearly a year later, calling on Mullenweg to stop restricting access to plugin data from people who are hosting themes and plugins on WordPress.org.

    “I talked to a bunch of folks at [WCUS] contributor day,” Paid Memberships Pro co-founder and CEO Jason Coleman said in response to Waldon’s tweet. “As far as I know, there isn’t any other current effort to update or replace the install count numbers or old ‘growth’ chart.’”

    Coleman put together a draft proposal with some ideas from his conversations. The document describes a common scenario where plugin developers are left in the dark about the growth or decline of their plugins’ active installations:

    Imagine a developer with a plugin with 150k active installations. That developer has effectively 0 quantitative feedback on whether users of his plugin are growing or falling. The download count has a trend, but there is no separation between new downloads and updates. The download count tracks developmental pace as much as user growth. A bump in downloads could be due to a security vulnerability being patched or an influx of new users. The current active installations count is severely rounded and offers no feedback until such a plugin either gains or loses 33% of its users, which are drastically different outcomes.

    Coleman contends that plugins hosted outside of WordPress.org are able to gather more meaningful metrics. Popular plugins have resorted to including features in non-WordPress.org add-ons or simply removing their extensions altogether from the repository for lack of data.

    His proposal includes a few metrics that would help developers better track their plugins, even if that data is only shown to the authors themselves:

    • Share a more accurate active installations count with the owners of a plugin.
    • Share more accurate version number counts with the owners of a plugin.
    • Differentiate the download count by type: website downloads, dashboard installs, dashboard downloads, updates, other (hits to the zip file).
    • Allow plugin developers to define custom event triggers to be tallied and displayed to the plugin owners on the plugins .org profile page.

    Coleman’s draft is still in progress. He was not immediately available for comment when I asked about the next step once the proposal is further developed.

    WordPress.org has always been the most popular distribution channel for the most widely used plugins, but the data available has not kept pace with developer and business needs. Releasing the raw data, while respecting any privacy limitations, would allow developers to extract their own interpretations of that data and allow services to present it in creative ways.

    At the very least, this data should be available to developers (even if it’s not public) to help them better track the trajectory of their plugins and the efficacy of their marketing efforts. More data can only serve to improve the WordPress ecosystem’s ability to continue powering a multi-billion dollar economy. There are undoubtedly many technical requirements for supporting the release of this data, and they need to be prioritized if WordPress.org is to continue attracting the best products for distribution.

    “This is not about vanity metrics or inflating numbers for marketing purposes,” Coleman said. “This is about getting valuable feedback on the relative use of a plugin hosted in the .org repository so developers can make informed decisions and investments in those plugins.”

    Go to source

  • ACF’s 2023 Annual Survey Results Reinforce Plugin’s Focus on Improving the Block Building Experience

    Advanced Custom Fields (ACF), one of the plugins WP Engine acquired from Delicious Brains in 2022, has published the results if its first annual survey. Although ACF reports more than 4.5 million active users, including PRO site installs, the survey only gathered feedback from 2,031 respondents.

    These results are more representative of the plugin’s developer community, as 81% of respondents are developers who maintain between 11-50 websites. 63% use version control for their codebase, and 27% manage dependencies with Composer.

    The survey showed that ACF is still an important tool for its early adopters, as 50% said they have been using it since its early days and 70% of all respondents use the plugin on all the websites they build.

    When asked what type of sites they are building, respondents had the option to choose multiple answers. Sites using Classic WordPress themes are the most popular followed by Hybrid themes, Block themes, and page builders. Surveying those who use the block editor, 56% report that they build blocks using ACF blocks.

    “It was cool to see the strong representation of hybrid and block themes,” WP Engine Product Marketing Manager Rob Stinson said. “It shows us that there is growing adoption of the modern WP editor experience amongst the PHP friendly crowd that is the ACF user base.

    “We had this scoped for upcoming releases anyway, but it reinforces our focus on improving the block building experience in ACF.”

    Among those ACF users building sites with page builders, the most popular selections include Elementor, Divi, Beaver Builder, and WPBakery Page Builder. Naturally, ACF Extended is the most popular extension used with ACF, followed by Gravity Forms, Yoast SEO, and ACF Better Search.

    Respondents demonstrated high confidence in those maintaining the plugin, as 98% of them are comfortable updating ACF to the latest version. They are also confident in continuing to build on top of WordPress, as 91% of survey participants said they are likely to continue with the platform. For a more detailed look at the questions and responses, check out the 2023 annual survey results on the ACF website.

    Go to source

  • Patchstack Reports 404 Vulnerabilities Affecting 1.6M+ Websites to WordPress.org Plugins Team

    After an accumulation of undisclosed and unpatched vulnerabilities in plugins hosted on WordPress.org, Patchstack has reported 404 plugins to WordPress’ Plugin Review Team.

    “This situation creates a significant risk for the WordPress community, and we decided to take action,” Patchstack researcher Darius Sveikauskas said. “Since these developers have been unreachable, we sent the full list of those 404 vulnerabilities to the plugins review team for processing.”

    Ordinarily, reporting plugins to WordPress.org is a last resort for challenging cases after Patchstack fails to find a way to contact the vendors. In this case, many of these plugin authors have included zero contact information in their extensions or are not responding to communication attempts. Patchstack has characterized it as a “zombie plugins pandemic” due to the overwhelming number of abandoned plugins affecting more than 1.6 million sites.

    The WordPress.org Plugins Team has acted on the report by closing more than 70% of the plugins. In June, the team added six new sponsored volunteers and opened applications for more team members but have struggled with managing a formidable backlog of plugins waiting to be reviews. The backlog is climbing higher and is now over 1,119 plugins with a 71-day wait time.

    Adding plugin vulnerability issues, where hundreds have to be closed, only adds to how long developers have to wait to get new plugins reviewed.

    As of August 31, 2023, Patchstack reports the following stats associated with these reports to WordPress.org:

    • 404 vulnerabilities
    • 358 plugins affected
    • 289 plugins (71,53%) – Closed
    • 109 plugins (26,98%) – Patched
    • 6 plugins (1,49%) – Not closed / Not patched
    • Up to 1.6 million active installs affected
    • Average installs per plugin 4984
    • Highest install count 100000 (two plugins)
    • Highest CVSS 9.1
    • Average CVSS 5.8
    • “Oldest” plugin – 13 years since the last update

    Patchstack is urging developers to add their contact details to their plugins’ readme.txt and/or SECURITY.md files. To streamline security issue management, the company has created the Patchstack mVDP (managed vulnerability disclosure program) project, which is free for developers to join. Patchstack validates the reports that come through, rewards the researchers, and passes them to the vendor to be addressed.

    The company is also advocating for a dashboard alert when a plugin or theme is removed due to security reasons, as WordPress does not currently give the user this information. Their researchers will soon be submitting more reports that may result in closed extensions.

    “We are preparing more similar lists for the WordPress.org themes repository and repositories focused on premium products,” Sveikauskas said. “We are currently processing about extra 200+ similar vulnerabilities.”

    Go to source

  • 7 Best WordPress Podcast Plugins in 2023

    Podcasts are a great way to capture your audience by uploading audio and video episodes. However, producing quality content is as important as choosing the right podcasting tools to win your audience’s attention. A great tool should be compatible with your website and hosting service as well as support the video and audio files you […]

    Read More…

    The post 7 Best WordPress Podcast Plugins in 2023 appeared first on Hostinger Tutorials.

    Go to source

  • New Chrome Browser Extension Enables One-Click Plugin and Theme Testing with WordPress Playground

    WordPress Playground, an experimental project that uses WebAssembly (WASM) to run WordPress in the browser, makes it possible for users to quickly test plugins and themes without having to set up a local development environment.

    Ordinarily, testing a plugin or theme with Playground requires visiting playground.wordpress.net, which will instantly create a real WordPress instance with admin access without having to install PHP, MySQL, or Apache. It runs inside the browser using a SQLite database. Adding a plugin or theme to the instance is as easy as appending the slug to the URL when creating the test site:

    https://playground.wordpress.net/?plugin=gutenberg

    https://playground.wordpress.net/?theme=lemmony-agency

    A new Chrome browser extension, created by LUBUS, a development agency, makes this even easier by adding a “Playground” button to theme and plugin pages on WordPress.org. Users can fire up a sandbox instance to test drive a theme or plugin in just one click.

    I tested the extension and it works as advertised. It’s a neat little shortcut for launching a Playground instance without having to remember the URL or get the plugin/theme’s slug to append to it. The video below shows a site created with a selected plugin installed in under 20 seconds.

    “We have been using Playground internally a lot for testing out plugins, and quick demos for internal or client meetings,” LUBUS founder Ajit Bohra said. “We often find a plugin or theme which we would like to test drive. It involves copying the slug of the theme or plugin and using them in the URL. To make this quick we thought of building and quick browser extension to add a button on wordpress.org to quickly launch a plugin or theme in the Playground.”

    Bohra posted his process of creating the extension in a thread on X. He used the Plasmo framework, which offers a dedicated runtime for building browser extensions, taking the project from idea to built in approximately 30 minutes.

    Bohra said the browser extension is currently a proof of concept that he would like to further extend with more settings based on feedback from users. He also hopes to collaborate with the Meta team in the future to see something like this added to the plugin and theme pages on WordPress.org so that users don’t have to rely on a browser extension.

    The Chrome extension is called “Open in WordPress Playground” and is available to the public for free on the Chrome Web Store. The code is open source on GitHub and open for contribution.

    Go to source

  • group.one Acquires BackWPup, Adminimize, and Search & Replace Plugins

    group.one, a European cloud hosting and digital marketing services provider, has acquired the BackWPup, Adminimize, and Search & Replace plugins from Inpsyde. Together the products have more than 1.1 million active installs and will join group.one’s growing portfolio of WordPress products, which include WP Rocket, Imagify, and Rank Math SEO.

    Inpsyde sold the plugins to focus more on its consulting and product services.

    “This sale lets us concentrate on our core competencies and work more closely with our clients, like PayPal, Payoneer, and Mollie, providing the know-how to develop and reach their full potential with new avenues for advancement,” Inpsyde CEO Alex Frison said.

     The acquired plugins will be managed by the development team at WP Media, one of group.one’s brands, expanding its offerings beyond optimization and SEO to include backup and site management capabilities.

    “Backup and recovery solutions are crucial to protect websites against data loss and we look forward to further developing BackWPup, along with Adminimize and Search & Replace,” group.one CEO Daniel Hagemeier said. “Together with WordPress hosting from WP.one and one.com, and our flagship products WP Rocket, Imagify, and Rank Math SEO, WordPress users can now come to group.one to optimize, secure, maintain and promote their online presence.”

    When asked what specific features are being prioritized on the immediate roadmap, group.one representative Simon Kraft said “the smooth transition over to WP Media” is their focus following the sale. He was unable to comment on whether the commercial versions of the acquired plugins would be subject to any pricing changes.

    Go to source

  • Best 7 WordPress Auction Plugins and How to Create an Auction Website

    If you sell valuable collectibles or are passionate about online bidding, an auction site can help you achieve both goals. Building a bidding platform simplifies the auctioning process to make money online. You can do so using WordPress, a popular content management system (CMS). Easily add auction functionality to your website with WordPress plugins, eliminating […]

    Read More…

    The post Best 7 WordPress Auction Plugins and How to Create an Auction Website appeared first on Hostinger Tutorials.

    Go to source

  • WordPress Plugin Review Team Addresses Backlog of 900+ Plugins, Implements Strategies to Improve Approval Process

    WordPress’ Plugin Review team is wading through a backlog that was over 900 plugins awaiting approval earlier this week. The current count has 870 plugins sitting in the review queue, with an average wait time of 61 days before initial review.

    WordPress developer Marcus Burnette drew attention to the matter on Twitter after submitting a plugin he created to display a gallery of your own WordPress Photo Directory photos on your website. Other developers commented on his post, reporting that their recently-approved plugins took two months.

    WordPress Executive Director Josepha Haden Chomphosy responded with an invitation to contributors who want to learn how to review plugins and apply to join the team.

    The volunteer team responsible for reviewing plugins has undergone significant restructuring after the departure of long-time contributor Mika Epstein. In June, the team added six new sponsored volunteers and opened applications for more team members. They have selected new team reps and have more than 20 applicants who have expressed interest in volunteering.

    “The first challenge we found during our onboarding was the fact that a lot of processes were not clearly documented,” newly selected team rep Francisco Torres said in a recent update. “We asked A LOT of questions during this process and ensured that all the answers Mika shared with us were added to the team’s internal docs. This effort should make it a lot easier for new contributors to join the team down the road.

    “We have also improved our internal tools to catch the most common coding mistakes and have built our predefined responses into the output provided by this tool. We still review this content manually before sending out replies, but by merging the two tasks into one (reviewing the code and drafting the message) we have been able to cut down review time considerably.”

    In strategizing ways to cut through the formidable plugin backlog, the team has begun speeding up the process by performing a cursory initial review, followed by a more thorough one once the plugin author has fixed the most obvious issues.

    “In order to tackle the backlog faster, we’re now spending less time on initial reviews,” Torres said. “We begin checking issues that take us less time, and then as soon as we spot one or two issues with the plugin that would prevent it from being approved, we email the plugin author to ask them to fix the initial issues. If the author gets back to us with those first fixes, then we proceed with an in-depth review.”

    A two-month wait can be demoralizing for developers who are excited to share their open source plugins with the world. Now that the whole process is getting documented and refined to be more efficient, the Plugin Review Team will be better able to onboard new reviewers and put them in place to tackle the backlog.

    Go to source

  • Kadence Blocks 3.1.11 Patches Critical Vulnerability

    The Kadence Blocks plugin, which is used on more than 300,000 WordPress sites, has patched a critical vulnerability in its Advanced Form Block file upload capability. Version 3.1.11, released on August 8, 2023, patches the security issue with the form uploads.

    The plugin’s development team is getting out ahead of the situation by posting an advisory on their blog, with a short description of the vulnerability and its potential for exploit.

    The Kadence Advanced Form Block, introduced in Kadence Blocks 3.1, offers site owners the ability to add a file upload capability to their site. The code within the Advanced Form Block had insufficient tests to limit what types of files can be uploaded. This could allow attackers to upload a file claiming to be a valid image type that actually contained malicious PHP code. That PHP code could be malicious, and in so doing, take over a vulnerable WordPress website. Exploiting this vulnerability would require a settings at the server level that would be considered insecure. Most premium hosting providers secure upload folders from PHP execution at the server level, though many budget hosting providers do not.

    Kadence Blocks developer Ben Ritner said sites that are not using the Advanced Form Block file upload capability are not subject to this vulnerability. At this time the vulnerability is not known to have been exploited.

    Kadence Blocks users are encouraged to update immediately and check for unexpected users, admin accounts, and content changes. The advisory also includes ways to make file uploads more secure, including limiting file type, adding authentication, and scanning for viruses.

    Go to source