Tag: plugins

  • WordPress.org Enables Commercial and Community Filters on Plugin and Theme Directories

    During the 2022 State of the Word, Matt Mullenweg announced a plan to add new “Community” and “Commercial” taxonomies for the theme and plugin directories that would help users more quickly ascertain the purpose of the extensions they are considering. Shortly after the announcement, instructions were published for theme and plugin authors to opt into the new taxonomies.

    The new filters are now enabled on both the theme and plugin directories, giving users the ability to quickly sort between free community extensions and those with commercial upgrades. Anything with a “pro version” should be designated as Commercial. These usually come with some upsells for more features than are offered in the free version. So far, the number of themes identified as commercial vastly exceed the number of community themes.

    In the Plugin directory, extensions designated as free are nearly equal those designated as commercial. Many of the most widely used plugins have already been identified as commercial, including Yoast SEO, Jetpack, Akismet, Elementor, WooCommerce, All-in-One WP Migration, and more. Examples of community plugins include the WordPress Importer, Classic Editor, Classic Widgets, Gutenberg, Performance Lab, and Debug Bar.

    In both directories it appears only a small percentage of authors have designated their extensions using the commercial or community taxonomies. At this time, use of the taxonomies is not required. This gave rise to some questions in the comments of the announcement.

    “Would a better classification system would be to just have either no label for the majority, and then something closer to ‘includes paid upgrades’ that just implies they also offer additional services on top of their free (and often fully functional) version?” WordPress developer Kevin Batdorf said.

    “All plugins are open source regardless of whether they sell something, and that doesn’t make those developers any less passionate about open-source. Nor does it imply non-commercial plugins have any less features, or that the level of dedication to support is any less dedicated.”

    Batdorf also asked if use of the taxonomies would be a requirement in the future, because, at the moment, their low usage could give some plugins an advantage under these new classifications.

    “Should it also be a requirement?” he said. “Otherwise this also seems like something to be gamed for visibility. Do Community or Commercial (or neither) plugins show higher install growth? I guarantee you people are tracking this already.”

    WordPress’ Meta team is seeking feedback on the current implementation. Automattic-sponsored contributor Steve Dufresne said “work is continuously underway to improve the browsing experience and refine the visual aspects of the Theme and Plugin Directory as part of the site redesign.” The new filters will be incorporated into the upcoming redesign changes that have been slowly rolling out across WordPress.org.

    These filters will also be making their way into the admin theme and plugin browsers, so users can access them from wherever they search for extensions. In the meantime, users and theme and plugin developers can leave feedback via Meta Trac on the specific tickets outlined in the announcement, as the team continues to iterate on the project.

    Go to source

  • Mastering Your Content Strategy with a PublishPress Editorial Calendar

    Mastering your content strategy with a WordPress editorial calendar is crucial for any serious content creator or marketer looking to streamline their workflow and enhance productivity. This guide will introduce PublishPress as one of the most popular content calendar plugins. Additionally, it will explain how to customize it for your website’s needs.

    The post “Mastering Your Content Strategy with a PublishPress Editorial Calendar” first appeared on WP Mayor.

    Go to source

  • 7 Reliable AI Plugins for WordPress in 2023 to Help Build and Manage Your Website

    Whether you’re searching for basic or advanced AI plugins for WordPress, the leading content management system (CMS) offers a big selection. Together with the top WordPress hosting service, AI makes building and managing your website more efficient and faster. More specifically, AI-powered WordPress plugins can help you with tasks like content creation, image generation, search […]

    Read More…

    The post 7 Reliable AI Plugins for WordPress in 2023 to Help Build and Manage Your Website appeared first on Hostinger Tutorials.

    Go to source

  • Effective CRM Data Cleansing Strategies for WordPress Users

    Wow, we’re thrilled! We’ve just installed Groundhogg, and its potential for managing customer communications has us buzzing. We’re seeing possibilities everywhere! Think streamlined workflows, personalized customer touchpoints, and ultimate CRM data organization. Groundhogg is truly a game-changer for us.

    While working on this integration I found the need to clean our own CRM data and thought I would share some of the tasks and information I encountered while undertaking this project.

    The post “Effective CRM Data Cleansing Strategies for WordPress Users” first appeared on WP Mayor.

    Go to source

  • How to Optimize Kinsta WordPress Hosting with WP Rocket

    Your site can run faster than ever, specifically when you use Kinsta with WP Rocket. We’ll show you how to set it up!

    The post “How to Optimize Kinsta WordPress Hosting with WP Rocket” first appeared on WP Mayor.

    Go to source

  • Best WordPress Multilingual Plugins

    WordPress has become one of the most popular open source Content Management Systems, and now powers and supports more than 60,000,000 blogs and sites from all over the world.

    Since WordPress is so widely used all over the world, there is an inherent need for site contents to be displayed in different languages. Now with eCommerce sites also being constructed with WordPress, it is quite important to make one single site with multiple language compatibility. This can make the sites usable for people speaking different languages. Multilingual plugins from WordPress are developed for this very purpose.

    The post “Best WordPress Multilingual Plugins” first appeared on WP Mayor.

    Go to source

  • MariaDB Health Checks Plugin Now Available on WordPress.org

    A new MariaDB Health Checks plugin is now available on WordPress.org, thanks to the efforts of contributors involved in the 2023 CloudFest Hackathon which took place in Germany. MariaDB is a popular open source database used by those looking to further scale their websites, as it is generally faster than MySQL with better support for a concurrent number of connections.

    “At the moment it appears WordPress is dominating the PHP world, so this seemed to be the perfect target,” MariaDB Foundation Chief Contributions Officer Andrew Hutchings said about creating the plugin at the hackathon.

    “The MariaDB Foundation loves WordPress (I’m writing this post in WordPress right now) so it seemed like a logical project.”

    The plugin helps users debug their MariaDB databases by displaying important information, such as logs, locale, connections, character set and collation, and options. It also shows a graph of the number of queries and the execution time over the last 24 hours.

    The plugin also integrates with WordPress’ Site Health feature with two checks: an end-of-life check and a check for whether Histograms have been run. Histograms are an optimizer that can help improve MariaDB performance, and the plugin enables calculation of histograms to run on WordPress tables with the click of a button under the plugin’s Tools menu.

    “There are a few features now and it is a good framework to add more features to in future,” Hutchings said. “This is a community project and is open to suggestions and pull requests. This is a project that we at the MariaDB Foundation want to support in the future.”

    MariaDB Health Checks is developed on GitHub where developers can follow the plugin’s progress, contribute to new features, and report bugs.

    Go to source

  • ACF Plugin’s Reflected XSS Vulnerability Attracts Exploit Attempts Within 24 Hours of Public Announcement

    On May 5, Patchstack published a security advisory about a high severity reflected cross-site scripting (XSS) vulnerability in ACF (Advanced Custom Fields), potentially affecting more than 4.5 million users. WP Engine patched the vulnerability on May 4, but the Akamai Security Intelligence Group (SIG)  is reporting that attackers began attempting to exploit it within 24 hours of Patchstack’s publication.

    “Once exploit vector details are publicly released, scanning and exploitation attempts rapidly increase,” Akamai Principal Security Researcher Ryan Barnett said. “It is common for security researchers, hobbyists, and companies searching for their risk profile to examine new vulnerabilities upon release. However, the volume is increasing, and the amount of time between release and said growth is drastically decreasing. The Akamai SIG analyzed XSS attack data and identified attacks starting within 24 hours of the exploit PoC being made public.

    “What is particularly interesting about this is the query itself: The threat actor copied and used the Patchstack sample code from the write-up.

    Patchstack’s security advisory includes a breakdown of the vulnerability, sample payload, and details of the patch.

    Although the vulnerability, assigned CVE-2023-30777, was promptly patched, and WP Engine alerted its users the same day, site owners have been slow to update to the latest, patched version of the plugin (6.1.6). Only 31.5% of the plugin’s user base are running version 6.1+, leaving a significant portion still vulnerable unless they are protected by additional security measures like virtual patches.

    “Exploitation of this leads to a reflected XSS attack in which a threat actor can inject malicious scripts, redirects, ads, and other forms of URL manipulation into a victim site,” Barnett said. “This would, in turn, push those illegitimate scripts to visitors of that affected site. This manipulation is essentially blind to the site owner, making these threats even more dangerous.”

    Barnett noted that attackers using the sample code from Patchstack indicates these are not sophisticated attempts, but the comprehensive security advisory makes vulnerable sites easy to target.

    “This highlights that the response time for attackers is rapidly decreasing, increasing the need for vigorous and prompt patch management,” Barnett said.

    Go to source

  • ACF Launches New Annual Survey

    WP Engine has launched an annual survey for Advanced Custom Fields (ACF), one of the plugins it acquired from Delicious Brains in 2022. ACF reports more than 4.5 million active users, including PRO site installs, and WP Engine Product Manager Iain Poulson reports that the plugin is “growing in every way since the acquisition.” ACF has added more users, features, and releases, along with community building efforts like bi-weekly office hours.

    This is the first time ACF has surveyed its user base about how they are building sites with WordPress and what can be improved. The survey starts with questions about the contexts in which professionals are using ACF and the volume and types of sites they are building. Respondents are asked about how they edit their sites, the type of license they are using, how often the reach for ACF in their toolbox, and which ACF features they use most often (i.e. REST API, ACF Blocks, Options pages, ACF Forms, Post Types Registration, etc.).

    The survey is on the lengthier side with an estimated 15 minutes to complete. As ACF is a critical and indispensable part of many WordPress developers’ workflow, helping to shape its future development may be worth the time. WP Engine has also added a few questions that may only be tangentially related to ACF, such as where users are hosting their WordPress sites and what they use for local development.

    “It’s our primary method for gathering insights and feedback from the WP community on what they would like to see in ACF,” WP Engine Product Marketing Manager Rob Stinson said. He also related the importance of previous customer feedback that helped ACF’s team plan and implement features like registering CPTs and Taxonomies (v6.1).

    “In the near term, we’re working on bringing a UI to register Options Pages which is a PRO plugin feature, some long requested features like bi-directional relationship fields and improvements to conditional logic rules for taxonomy fields,” Poulson said. “We will also be focussing a release on more ACF Blocks features and improvements. The survey won’t likely change those planned features, and the initial results are validating our planned work on ACF Blocks.”

    The survey ends May 19, 2023, and WP Engine plans to publish an aggregated and anonymized version of the results soon after the data is collected.

    Go to source

  • Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

    Essential Addons for Elementor, a plugin with more than a million active installs, has patched an unauthenticated privilege escalation vulnerability in version 5.7.2. The vulnerability was discovered on May 8, 2023, and reported by Patchstack researcher Rafie Muhammad. It was given a 9.8 (Critical severity) CVSS 3.1 score and is not yet known to have been exploited.

    Muhammad outlined the vulnerability in a security advisory published today:

    This plugin suffers from an unauthenticated privilege escalation vulnerability and allows any unauthenticated user to escalate their privilege to that of any user on the WordPress site.

    It is possible to reset the password of any user as long as we know their username thus being able to reset the password of the administrator and login on their account. This vulnerability occurs because this password reset function does not validate a password reset key and instead directly changes the password of the given user. 

    The plugin’s authors published the patch today, on May 11, with the following note in the changelog:

    5.7.2 – 11/05/2023
    Improved: EA Login/Register Form for Security Enhancement
    Few minor bug fixes & improvements

    The vulnerability affects sites using versions 5.4.0 to 5.7.1 of Essential Addons for Elementor. Users are advised to update to the latest version 5.7.2 immediately now that Patchstack has published the proof of concept for exploiting it.

    Go to source