The Weekly round up of news, tips, and information to help you create the best possible WordPress website. This is a weekly round up of WordPress news I have accumulated from across the web some old some new but always interesting. The new relates to WordPress and sometimes other areas of the web. It often has a focus on security and more.

Round up of WordPress News and Tips October 2, 2017

The Weekly round up of news, tips, and information to help you create the best possible WordPress website. This is a weekly round up of WordPress news I have accumulated from across the web some old some new but always interesting. The new relates to WordPress and sometimes other areas of the web. It often has a focus on security and more.The Weekly round up of news, tips, and information to help you create the best possible WordPress website.

This is a weekly round up of WordPress news I have accumulated from across the web some old some new but always interesting. The new relates to WordPress and sometimes other areas of the web. It often has a focus on security and more.

We try to have news here that is not only important to help you with your website as well as new from the #wpdrama scene and more to share.

Some of the news here will be of interesting links to not only articles but training materials and other sources I can find online that will help you create a better WordPress website.

 


This week we have the following news for you.

How to Use Domain Mapping When You’re Not Running Multisite

https://premium.wpmudev.org/blog/domain-mapping-without-multisite/Our Domain Mapping plugin makes mapping domains super easy in Multisite. It lets you create as many sites as you want in one WordPress installation and then make them all behave as if they’re separate sites echo on their own domain.

But sometimes you want to map a domain when you’re not running Multisite. You’ve created a site in its own WordPress installation somewhere on your server, maybe in a subdirectory, but you want to direct a domain name to it and have that show up in the browser instead of your own domain with the subfolder or subdomain showing up. Read original article here…. premium.wpmudev.org

How to Track Post Changes by Adding a History Feature to WordPress

https://www.elegantthemes.com/blog/tips-tricks/how-to-track-post-changes-by-adding-a-history-feature-to-wordpress?utm_source=Elegant+Themes&utm_campaign=b5104ca772-WordPress_Daily&utm_medium=email&utm_term=0_c886a2fc0a-b5104ca772-51249745If you’re running a website with multiple contributors, it can be hard to track post changes in WordPress itself. This can become a problem if you’re trying to identify the source of an error, or keep tabs on your writers’ activity.

Finding a way to track post changes in WordPress enables you to keep logs of practically all of the activity for your posts and pages. For this article, we’ll talk about why this functionality can help you and how to implement it in three simple steps. Let’s get to it! Read original article here…. elegantthemes.com

How to Run a Contest with WordPress (and Plugins to Help You Do It)

https://premium.wpmudev.org/blog/contest-plugins-wordpress/About a month ago, a woman named Mavis Wanczyk won a monster Powerball payout of $758.7 million. Wanczyk wasn’t the only winner that night either. In a store nearby, someone else bought a ticket worth $1 million. There were also other winners from this single Powerball play—9.4 million people (or, rather, tickets) to be exact.

Now, if that isn’t proof enough of how much people love entering contests in the hopes of winning something (no matter what sort of odds are stacked against them), I don’t know what is. Read original article here…. premium.wpmudev.org

Handling Form Submissions in WordPress with Admin-Post and Admin-Ajax

https://premium.wpmudev.org/blog/handling-form-submissions/WordPress provides incredible support for you to work with form submissions in your application. Whether you add a form in the admin or public facing areas, the built-in mechanism with the admin-post and admin-ajax scripts will allow you to handle your form requests efficiently.

In this article, I’ll show you how to handle custom form submissions using the WordPress API. I’ll walk you through the process of adding a custom form in the admin area of a plugin, handle the form submission via an HTML as well as an AJAX request, and write the form handler in PHP to validate, sanitize and process the form input. Read original article here…. premium.wpmudev.org

20 of Google’s limits you may not know exist

http://searchengineland.com/20-googles-limits-may-not-know-exist-281387Google has a lot of different tools, and while they handle massive amounts of data, even Google has its limits. Here are some of the limits you may eventually run into.

Many of the data reports within Google Search Console are limited to 1,000 rows in the interface, but you can usually download more. That’s not true of all of the reports, however (like the HTML improvements section, which doesn’t seem to have that limit).

The limit for the number submitted is higher, but you will only be shown 200. Each of those could be an index file as well, which seems to have a display limit of 400 site maps in each. You could technically add each page of a website in its own site map file and bundle those into site map index files and be able to see the individual indexation of 80,000 pages in each property… not that I recommend this. Read original article here…. searchengineland.com

 

 


This week we have the following Security News for you.

Malicious plugin installed backdoor on 200,000 WordPress websites

https://www.scmagazine.com/malicious-plugin-installed-backdoor-on-200000-wordpress-websites/article/688878/A very persistent malicious actor added a backdoor to a WordPress plugin called Display Widgets that installed backdoors on possibly 200,000 websites since June 21.

The hacker used the open-source Display Widgets plugin, which lets users control how their WordPress plugins appear on their sites, as the delivery mechanism for the backdoor. Although the number of potentially infected sites is large, what is almost as impressive is the hacker’s persistence. The infected plugin was repeatedly removed from the site by WordPress.org between June 22 and September 8 with the hacker dutifully replaced it.

It was finally removed for good on September 8. Read original article here…. scmagazine.com

60 Abandoned WordPress Plugins

https://pressable.com/blog/2017/09/14/60-abandoned-wordpress-plugins/WordPress security threats are on the rise. In some cases, hackers can gain control over WordPress sites. Now, the question arises, how can you secure your WordPress sites?

A major cause of security breaches in WordPress sites is outdated plugins and themes. These elements of a site can be particularly vulnerable to exploitation, and hackers are well aware of this. If a plugin hasn’t been updated during the past 2 years, it is categorized as an abandoned, or outdated plugin. Moreover, it may pose compatibility issues with WordPress. Read original article here…. pressable.com

7 Signs Your WordPress Website Has Been Hacked

http://domainnamewire.com/2017/08/24/7-signs-your-wordpress-website-has-been-hacked/One of the reasons WordPress is so popular as a content management system is because of its airtight security (read: it’s rare ability to be hacked). But the truth is, 136,640 attacks are happening per minute to WordPress websites across the globe.

That’s a scary thought.

In fact, weak passwords, domain or hosting level breaches, insecure themes and plugins, and even an outdated WordPress core may cause your website to become more vulnerable than normal. Read original article here…. domainnamewire.com

 

 


And now for something older in the past article collections.

How to Beat Procrastination and Get More Done on Your WordPress Site

http://www.wpexplorer.com/beat-procrastination-wordpress/Everyone procrastinates now and then, but some people suffer much more than others. If you feel that procrastination is negatively affecting your productivity, then it is time to do something about it.

In this article we will look at why people procrastinate and what you can do about it. We discuss the importance of being clear on your goals and knowing your distractions and other weaknesses. We then consider productivity tips and tricks to help you maintain motivation and keep focused. Read original article here…. wpexplorer.com

How to Become a WordPress Professional in Your Free Time

https://premium.wpmudev.org/blog/become-wordpress-professional/Getting established as a WordPress pro isn’t easy. If you want to freelance or set up a WordPress business, you’ll need to build up a list of clients and establish a reputation for yourself. And if you’re looking for a WordPress job, you’ll need to demonstrate that you’ve got experience with WordPress and can work with it at a professional level.

But all this takes time learning and preparing, which you won’t get paid for. Unless you’re lucky enough to have an employer who’ll pay for you to learn WordPress (and give you paid time to do it), or who’ll help you learn marketing and business skills (working for a startup can be helpful), you’ll need to do it in your own time. Read original article here…. premium.wpmudev.org

The Complete Guide to the WordPress Theme Customizer

https://premium.wpmudev.org/blog/wordpress-theme-customizer-guide/WordPress 4.7 was released with a ton of great new features (which you can check out here), including some user experience and user interface upgrades to the theme Customizer.

In case you’re hearing about the Customizer for the first time, it’s a feature in the WordPress admin (go to Appearance > Customize) that allows users to tweak theme settings using a WYSIWYG interface and customize a theme’s colors, fonts, text, and pretty much anything else you want to change. Read original article here…. premium.wpmudev.org

6 Steps to Building a WordPress Maintenance Business

https://www.sitepoint.com/6-steps-to-building-a-wordpress-maintenance-business/Recurring revenue is the Shangri-La for business owners. Rather than scrapping and fighting and hunting for new clients, you have the same clients coming to you again, providing you with a steady stream of income. It takes away the stress of having to dig up new streams of revenue and allows you to start planning ahead.

But if you’re a WordPress designer or developer, you may be a bit perplexed about this whole “recurring revenue” thing. You make your money when clients need something new, like a website refresh for a site that looks like it was designed when MySpace was hot. You essentially have to wait for them to decide they want to change things. The whole idea of regular income feels like a mystery. Read original article here…. sitepoint.com

Tom McFarlin to Launch Marketplace for Blogging Plugins, Finds New Maintainer for WordPress.org Plugins

https://wptavern.com/tom-mcfarlin-to-launch-marketplace-for-blogging-plugins-finds-new-maintainer-for-wordpress-org-plugins?utm_source=The+WhiP+by+WPMU+DEV&utm_campaign=dae7d0771e-The_WhiP_Lifes_Plug_It_In_Plug_It_In+_01_13_17&utm_medium=email&utm_term=0_74fb43fd55-dae7d0771e-102893693Daily blogger and plugin author Tom McFarlin has found a new maintainer for five of his WordPress.org plugins. Within two days of putting the plugins up for adoption, McFarlin announced that Philip Arthur Moore will be taking over Category Sticky Post, Comment Tweets, Single Post Message, Tag Sticky Post, and Tipsy Social Icons. Moore, who is currently working as CTO at Professional Themes, has inherited roughly 10,000 users overnight in the transfer of maintainership.

WordPress.org plugin adoption stories are few and far between. The most common scenario for an orphaned plugin is to languish in the directory until it disappears from search results (with the exception of exact matches) after two years of no updates. In McFarlin’s case, he was looking to tie up some loose ends before shifting Pressware’s focus to launching Blogging Plugins, a marketplace for extensions that streamline WordPress for regular bloggers. Read original article here…. wptavern.com

 

Well that’s a wrap for this week more next week from WP Plugins A to Z.

 

This is a weekly round up of WordPress Security news for July 24, 2017 that I have accumulated from across the web. Some is old WordPress news some new WordPress news but always interesting. pay attention this stuff your security is at stake.

Round up of WordPress Security News and Tips July 24, 2017

This is a weekly round up of WordPress Security news for July 24, 2017 that I have accumulated from across the web. Some is old WordPress news some new WordPress news but always interesting. pay attention this stuff your security is at stake. The Weekly round up of Security News, Tips, and information to help you keep your WordPress website safe and secure.

This is a weekly round up of WordPress Security news I have accumulated from across the web some old some new but always useful. The new relates to keeping a WordPress secure.

 


This week we have the following Security News for you.

Your WordPress plugins might be silently losing business data

https://venturebeat.com/2017/07/19/your-wordpress-plugins-might-be-silently-losing-business-data/If your WordPress site uses third-party plugins, you may be experiencing data loss and other problematic behavior without even knowing it.

Like many of you, I’ve become quite attached to WordPress over the past 15 years. It is by far the most popular content management system, powering 28 percent of the Internet, and still the fastest growing, with over 500 sites created on the platform each day. Considering myself well versed in the software, I was surprised to discover — while working on a digital design project for a client — what could be the Y2K of WordPress. Many WordPress plugins are suffering data loss, and it looks like this problem will soon explode if not properly addressed. Read original article here…. venturebeat.com

WordPress Sites at Risk From PHP Code Execution

https://securityintelligence.com/news/wordpress-sites-at-risk-from-php-code-execution/New attacks against unfinished installations of WordPress aim to give attackers admin access and the opportunity to run PHP code.

The campaign, which was revealed by security specialist Wordfence, peaked during May and June when attackers targeted recently installed, but not configured, instances WordPress, SecurityWeek reported. Outsiders can use a successful attack to take over the new WordPress website and then potentially gain access to the entire hosting account. Read original article here…. securityintelligence.com

5 Simple Ways To Secure Your WordPress Website, Without Plugins

http://www.business2community.com/cybersecurity/5-simple-ways-secure-wordpress-website-without-plugins-01813854#a2wEZSsx4z7qBUU2.97Any time security is brought up with WordPress, the first thought is external sources that could be used to protect your website. But in fact hardening WordPress must start with the install and the administrator of the website. Websites are no longer like sheets of paper, they are dynamic and like software that require strong protection that has to start with the most basic things.

That’s what we are writing about here. Many of these issues arise when we, Element 502, take over the security, SEO and administration of a WordPress website. Read original article here…. business2community.com

WordPress Performance Testing: Why, How & Which Tools to Use

http://www.wpexplorer.com/wordpress-performance-testing/Tons of articles written as the one guide to performance on WordPress, tons of content dedicated to the subject at hand but, what about the tools we use for measurement?

The online and software tools we use are a big part of the equation. A wrong tool or improper results can lead you astray. Today we are going to do the exact opposite, today we are going to benchmark the benchmarks and see if we can come up with a better idea of what’s good, what’s acceptable and what should be definitely avoided when trying to analyze our sites in our need for speed. Read original article here…. wpexplorer.com

 

 

 

 

 

Well that’s a wrap for this week more next week from WP Plugins A to Z.

The Weekly round up of Security News, Tips, and information to help you keep your WordPress website safe and secure. This is a weekly round up of WordPress Security news I have accumulated from across the web some old some new but always useful. The new relates to keeping a WordPress secur

Round up of WordPress Security News and Tips

The Weekly round up of Security News, Tips, and information to help you keep your WordPress website safe and secure. This is a weekly round up of WordPress Security news I have accumulated from across the web some old some new but always useful. The new relates to keeping a WordPress securThe Weekly round up of Security News, Tips, and information to help you keep your WordPress website safe and secure.

This is a weekly round up of WordPress Security news I have accumulated from across the web some old some new but always useful. The new relates to keeping a WordPress secure.

 


This week we have the following Security News for you.

The Ultimate Guide to WordPress Security

https://premium.wpmudev.org/blog/ultimate-guide-wordpress-security/Hackers attack WordPress sites both big and small with over 90,978 attacks happening per minute. Fortunately, there are numerous ways you can protect your WordPress site.

Today, I want to share with you how you can make your WordPress site’s security air tight with basic through to advanced techniques. I’ll also explore how WordPress can be vulnerable to attacks, how hackers compromise websites, how to troubleshoot a hacked site and security plugins you can install.

Feel free to jump down to any section you want to see first: Read original article here…. premium.wpmudev.org

Hackers Are Using Automated Scans to Target Unfinished WordPress Installs

https://www.bleepingcomputer.com/news/security/hackers-are-using-automated-scans-to-target-unfinished-wordpress-installs/Experts from security firm Wordfence say they have observed a wave of web attacks that took aim at unfinished WordPress installations.

These are sites where a user had uploaded the WordPress CMS, started but never finished the installation process.

These sites remained open to external connections, and anyone could have accessed their install panel and complete the installation on behalf of the user.

According to Wordfence, this is exactly what happened. For almost a month, starting with the end of May and through mid-June, an attacker had mass-scanned the Internet for WordPress installations that still featured their installation file. Read original article here…. bleepingcomputer.com

Rotate Your Site’s SALT Keys for Better Brute Force Protection

https://www.blogaid.net/rotate-your-sites-salt-keys-for-better-brute-force-protection/?utm_source=BlogAid+Newsletter&utm_campaign=7a1d335cb0-BlogAid_Blog_Posts5_12_2015&utm_medium=email&utm_term=0_7bdf20ec49-7a1d335cb0-710348757Your WordPress site has a set of master keys to protect your login.

They are called SALT keys.

And they need to be periodically rotated for better security from Brute Force attacks and/or having your site hacked.

Discover what your SALT keys do, where they are located, and how to rotate them.

When you input your username and password into the login screen of your WordPress site, they have to be checked against something to ensure they are correct.
https://api.wordpress.org/secret-key/1.1/salt/
Read original article here…. blogaid.net

Let’s Encrypt Passes 100 Million Certificates Issued, Will Offer Wildcard Certificates in January 2018

https://wptavern.com/lets-encrypt-passes-100-million-certificates-issued-will-offer-wildcard-certificates-in-january-2018Let’s Encrypt, the free and open certificate authority that launched in 2016, has issued more than 100 million certificates as of June 2017 and is currently securing 47 million domains. Earlier this year, the web passed a major milestone of getting more than 50% of traffic encrypted. Let’s Encrypt has been a major contributor to that percentage growing to nearly 58%.

“When Let’s Encrypt’s service first became available, less than 40% of page loads on the Web used HTTPS,” ISRG Executive Director Josh Aas said. “It took the Web 20 years to get to that point. In the 19 months since we launched, encrypted page loads have gone up by 18%, to nearly 58%. That’s an incredible rate of change for the Web.” Read original article here…. wptavern.com

Configuring WordPress to Always Use HTTPS/SSL

https://www.paidmembershipspro.com/configuring-wordpress-always-use-httpsssl/SSL encryption adds a layer of security to your website that makes it harder for malicious actors to collect personal information submitted through forms on your website.

This post will walk you through obtaining an SSL certificate (Let’s Encrypt or Other Providers), installing it on your web server (Let’s Encrypt or Other Providers), setting up your WordPress site to use HTTPS URLs, and fixing any “mixed content” type errors that come up when a page served over HTTPS links to non-HTTPS content. Read original article here…. paidmembershipspro.com

7 Tips to Improve WordPress Security

https://www.codementor.io/codementorteam/tutorials/tips-to-improve-wordpress-security-xep9sr558You just spent many days and sleepless nights to make a blog on WordPress or simply a WordPress website. Now that it is up and running, you are on cloud nine. What if, without a moment’s notice, it goes down due to a security loophole and you are left clueless. This is some nightmarish stuff, but fret not. Here is our detailed guide to help you cover some security patch for your WordPress website so that you have lesser things to take care of. However, you must accept the fact that maintain your WordPress website’s security is an ongoing job and will require you to get back at regular intervals to introduce new changes and make necessary fixes over time. So, let’s begin.

If you are new to the realm of WordPress, keep this glued to the back of your head that never use “Admin” as a username for any of your WordPress websites. You might consider this a smart choice, but hackers know this. Choose a unique username with capital letters along with special characters. Also, you can consider adding a new user providing it with administration privileges. This will be indeed a nice move to make. Read original article here…. codementor.io