Podcast: Play in new window | Download | Embed
Subscribe to WPPlugins A to Z on Apple Podcasts | Podcast Index | Email | RSS
Good morning, good afternoon, good evening, wherever you happen to be hiding out there on the globe today! Coming to you LIVE from . . .
We’ve got a couple of great in-depth plugins to cover for you, some recent news in both the WordPress World and the Tech World in general, and some awesome WordPress Tips!
Be sure to consume salt with all the water you are drinking – and a bag of chips does not really count for the week as my teenager has learned this summer! It sounds odd, but Kool-Aid is actually a good one for the summer time. Grab some up and toss it at the kids – they will drink plenty of the stuff, and it actually has what you need to properly absorb the liquid in it.
Also, Kool-Aid just has the smell of child hood for most adults, and its great to be passing on that nostalgia to the next generation!
A few reminders before we start the show today….
Reminders:
- Join us here in person every Monday at 12:00pm Pacific Time to enjoy our show!
- Show notes are added to wppluginsatoz.com within 24 hours of the show airing; you can find them either on the home page, or in the Podcast Vaults!
- This is a value for value show dear listeners, help us get some loven’ by hitting some like buttons, sharing an episode or two, or just turn our show on really loudly. We will catch somebodies attention!
If you stick around until the end, you will have a chance to hear some good questions – sometimes meant for the greenies, sometimes meant for the very experienced – and sometimes the questions are just completely random. Stick around and have a listen, might help! Or at least entertain!
(Don’t feel shy about sending in a message just to say hi! Send along suggestions, questions, recommendations, news, art – we always love to hear from our listeners!)
Let’s start the show with this weeks Featured Artist:
Artist:
Who is our artist today?!?
Today is…. Grok pulled it off
Grok! And he gave us our title too. He’s just such a useful little AI fella!
We would love some new art from our Producers out there! If you are so inclined, you can send it into us at https://wppluginsatoz.com/artwork/. If you need some inspiration, you can always go to our site wppluginsatoz.com and check out our Art Vaults – you will find the link for it on the left hand side.
We can NEVER have too much art!
Breaking News in the WordPress World at large!!
If you have anything you think should be added please send it into me at amber@wppro.ca!
News this week:
WordPress Vulnerability Report
(https://solidwp.com/blog/wordpress-vulnerability-report-july-30-2025) – In this report there are 113 vulnerabilities. 100 are plugins this week, with 13 Themes.
Plugins: 50 patched, 50 left to go!
Themes: 10 patched, 3 left to go!
WordPress Vulnerability Report from PatchStack
(https://patchstack.com/database/) – These guys always have the latest information on what is going on regarding the latest in vulnerabilities.
WordPress 6.9 roadmap: block comments, site editor updates, and an admin redesign
(https://www.therepository.email/wordpress-6-9-roadmap-block-comments-site-editor-updates-and-an-admin-redesign) – The admin redesign worries me a little… but it should be alright….
Following the roadmap that is now out we have a clearer picture of what’s being actively purused for the release that will be dropping on December 2.
Remember to not update your site, especially if it is an E-commerce site – until AFTER christmas! Just in case something goes wrong, you DO NOT want it to go wrong during this season!
Meta descriptions are dead – focus on Alt and Title Tags instead
(https://presswizards.com/meta-descriptions-are-dead-focus-on-alt-and-title-tags-instead) – This is a great article, and has a good argument on why meta descriptions are dead – although I do disagree to some extent. Having a meta description that will show in your search engine results is a very good thing, although focusing on your ALt and Title Tags is admittedly even more important these days as your pages and site overall will be graded on this by Google, whereas your Meta descriptions will not even be noticed for the overall grade. Great article, worth taking some time to read over it!
Agentic AI coming to WordPress: Hostinger and Elementor rolling out chat-based site management
(https://www.therepository.email/agentic-ai-coming-to-wordpress-hostinger-and-elementor-rolling-out-chat-based-site-management) – I personally do not see this going well at all. There is a reason most developers TURN OFF all of the automatic everything, it’s because AI while intelligent is not smart at all. Throughout this article there is talk about not having to bother messing with plugins, admin panels, just talking to the AI. You can read more about this here in the show notes by following the link, but I honestly do not think this is going to go over very well…
Patchstack mid-year report flags sharp rise in exploitable WordPress vulnerabilities
(https://www.therepository.email/patchstack-mid-year-report-flags-sharp-rise-in-exploitable-wordpress-vulnerabilities) – This is not great news for WordPress as Patchstack has reported 6,700 new vulnerabilities so far this year, with 41.5% deemed exploitable in real-world conditions, with most requiring no authentication. The report shows a sharp rise in both the volume and severity of the issues across the entirety of the WordPress ecosystem, showing a jump that is a wee bit concerning.
This time last year there was only a 30.4% show of vulnerabilities across the WordPress ecosystem. To make matters even worse, is that nearly 59% of the ones found so far in 2025 can be triggered without any authentication, highlighting the risks posed by automated, large-scale attacks. Follow the link for more information on this.
Unleash the Wapuu: a WordPress card game built with AI and open source spirit
(https://www.therepository.email/unleash-the-wapuu-a-wordpress-card-game-built-with-ai-and-open-source-spirit) – I just had to bring this out today, because this is actually pretty cool! Honestly I want this! You build your WordPress Dashboard, deploy your plugins, then sabotage your friends with malware. You block moves with perfectly timed ‘access denied’ cards – its a 108 card game that is all about engine building and sabotage with a heavy dose of WordPress in-jokes. Totally want one!
(Go visit WP Shout Comics OR Word Chronicles OR MonkeyUser.com for a fantastic brain break – my favourite today is this one!)
Some Extras – check out our Facebook or Twitter!
New QA report aims to bridge the gap between WordPress testing and Core Teams
(https://www.therepository.email/new-qa-report-aims-to-bridge-the-gap-between-wordpress-testing-and-core-teams)
Woo is getting louder: inside its new marketing strategy
(https://www.therepository.email/woo-is-getting-louder-inside-its-new-marketing-strategy)
Who will lead FAIR next? nominations now open for TSC co-chairs
(https://www.therepository.email/who-will-lead-fair-next-nominations-now-open-for-tsc-co-chairs)
Woo withdraws block theme submission, reconsiders successor to storefront
(https://www.therepository.email/woo-withdraws-block-theme-submission-reconsiders-successor-to-storefront)
The WP community collective lays foundations for project development and board explansion
(https://www.therepository.email/the-wp-community-collective-lays-foundations-for-project-development-and-board-expansion)
Google’s Danny Sullivan to keynote WordCamp US 2025 as speaker lineup begins to take shape
(https://www.therepository.email/googles-danny-sullivan-to-keynote-wordcamp-us-2025-as-speaker-lineup-begins-to-take-shape)
Finix launches WooCommerce plugin, enters crowded payments field
(https://www.therepository.email/finix-launches-woocommerce-plugin-enters-crowded-payments-field)
Inside enqueue: a new developer-focused WordPress event coming to APAC
(https://www.therepository.email/inside-enqueue-a-new-developer-focused-wordpress-event-coming-to-apac)
WordPress holds ground in higher ed but the sector is demanding more, according to new report
(https://www.therepository.email/wordpress-holds-ground-in-higher-ed-but-the-sector-is-demanding-more-according-to-new-report)
Google removes over 50 DEI groups from a list of groups it helps fund
(https://techcrunch.com/2025/08/04/google-removes-over-50-dei-groups-from-a-list-of-groups-it-helps-fund)
Perplexity accused of scraping websites that explicitly blocked AI scraping
(https://techcrunch.com/2025/08/04/perplexity-accused-of-scraping-websites-that-explicitly-blocked-ai-scraping)
Rogue’s Corner News and Extras
Be sure to go and check out the new and unique plugins now available from WPProAtoz.com!
Educational:
A great plugin that I am forking for improvements
https://github.com/Ahkonsu/wpproatoz-llms-txt-for-wp
Tip of the day
Talk about https://influencewp.com/ and the benefits of it for WP devs
Check out The Repo at https://therepo.org/ an alternative to the regular plugin repo.
Pet Peeve of the week
Rant of the week…. Woo Commerce and how they trick so many inexperienced users into adding unnecessary things such as jetpack, woo tax manager and the woo payment processer. Pinterest, TikTok integration and more little things.
Dragon Rating Time with John!
John’s Plugin
Shipping Live Rates for Canada Post for WooCommerce
https://wordpress.org/plugins/octolize-canada-post-shipping/
The Lowdown:
Use this free Canada Post WooCommerce Live Rates plugin to offer your customers the Canada Post shipping methods for domestic and international shipping.
Don’t waste your time, enter your Canada Post credentials and set everything up in your shop effortlessy in just 5 minutes!
Show your clients the Canada Post shipping services with their prices being dynamically calculated in the cart and checkout. Once the Canada Post API connection is established, the shipping cost for each Canada Post service is calculated real-time based on the products’ weight, shop location and delivery destination.
Rating 5 Dragons
WordPress Tips
We would love to hear some tid bit tips from some of our producers out there – what did you figure out by breaking something? Or what did you need to learn in order to help someone? You can send these tid bits into me at amber@wppro.ca
My tip to you today…
No site is too small for the financial bullies out there to pick on.
Right now we are experiencing a wave of bored lawyers and people in general who are looking to score off of sites that are ‘tracking and tracing’ people. A lot of these trackers and tracers that are being book marked are coming from the things we are willingly opting into for our site – like Google, and those plugins that anonymously track peoples movements on your site so that you can get a better idea of what they are interested in, where they spend most of their time.
Just so that you are aware, these plugins and programs don’t always wait for the cookie permissions, sometimes they jump the gun and they do a little bit of ‘pre-loading’ meaning that they are grabbing up the IP addresses and sending them off before the start gun of the cookie acceptance goes off.
My tip to you today is to do a little research and figure out if your site has any of these, because even if you are a little guy, it won’t matter sooner than you think. Sometime over the next little while these irritatants are going to become law, and you can and will absolutely be fined and charged for allowing this little bit of pre-loading to go on within your site.
And while you are doing some research on that, it may be a good idea to look at accessibility being added onto your site. Right now we are just starting to deal with this, so it is still very much a peripheral thing, but soon enough the bored lawyers are going to start in on that, and then the small fry’s will begin to feel the heat.
Keeping up to date, staying ahead of these kinds of things will help save you in the long run no matter if you are a big fish or small fry – we all feel the heat after the lawyers get involved.
Dragon Rating Time with Amber!
Amber’s Plugin
Bot-Lockout
https://wordpress.org/plugins/bot-lockout
The Lowdown:
For those who are looking for a bad bot eater plugin that works even when using most caching plugins, this one is for you!
As much as I love Black Hole for Bad Bots, they unfortunately do not work when you are using a plugin to cache on the same site. If you are interested in learning more on that you can check them out, they have information on their page.
It seems that a lot of the bad bot trap plugins have not been playing well with the caching plugins on the same site as them, and this plugin is one of the few that does work – it says with most caching plugins.
This plugin is also lightweight, has smart white-listing options, a fexable configuration, and it uses JavaScript-based cryptographic operations that are easy for humans but difficult for most bots to solve.
Once you install and activate this, you will find the dashboard for it under ‘Settings’>’Bot Lockout’.
On this dashboard you will see the following:
General Settings:
- This has a checkbox where you choose whether or not the bot lockout protection is enabled.
- You can personalise your block message, and choose how many seconds the challenge token remains valid. Default setting is 86400 seconds, which is 24 hours.
- Another checkbox where you choose whether to log the blocked attempts. These logs will be stored in the WordPress database.
Allowed User Agents:
- This is where you add in your list of user agents you WANT to have checking out your site. Default has Googlebot, Bingbot, DuckDuckbot, Slurp, and Baiduspider. You can add and remove at will!
Exclused Pages:
- here you can choose Pages or Paths that should be excluded from the bot protection. You enter partial URLs (e.g. “/ai/” or “/feed/”).
IP Whitelist:
- Here is where you place the IP addresses that should be allowed to access your site without completing the challenge. This is useful for testing, and also for trusted services.
Following along the tabs at the top we have ‘Logs’, where you can choose the maximum log age in days, default is at 30 – and you can choose the maximum log entries. The default for this is 1000.
And then we have ‘Test’, where you can “enter a user agent to test the cryptographic challenge. If the user agent is valid, a token will be generated. If the field is blank or malformed, “invalidtoken” will be shown.” Simply click on ‘Test Challenge’ and you will get a chance to see the results! It doesn’t seem to take very long at all, and every time you click it is a new test it seems, so you will only see the singular result.
The last tab along the top is ‘Support’. Here you have the Challenge Process written out step by step for you in simple easily digestible terms which is super useful! I like when they do that!
You also find the basic Security Features written out, the Perfomance Impace, and you have 4 different avenues offered up for you to get ahold of someone to help you with anything else you need help with regarding the plugin.
Testing this out on my ‘how the heck is it even still alive’ test site I found that this plugin plays well with others, and it does appear to be as lightweight as it claims to be!
Additionally they make a specific note citing that they are indeed compatible with CDN’s. For those that use CDN’s, this is good news!
The fact that this has such easy and straightforward settings is definitely major points on their side, and they work with a caching plugin too which is just awesome!
I highly recommend checking these guys out, the plugin is totally free and is a fantastic addition to any arsenol against those bots out there!
Rating: 5 Dragon
Miscellaneous Announcements from all:
Have an announcement like a meetup, or to announce you’ll be on stage at a WordCamp? Let us know and we will add it here and help get your news out to the world!
WP Build Tour Bhopal, M.P. – June 6 – August 31
WordPress Campus Connect Cartago – August 4-13
Summer Photo Contest 2025 – August 1 – 13
WordPress Campus Connect Ajmer – August 23 – October 11
WordCamp US – August 26-29
To see the entire list you can follow the link here in the show notes, then click on ‘More WordCamps’ right below the list of the next 5. https://central.wordcamp.org/
If you are interested in finding a WordPress Meetup somewhere around the world you can go check out the places here: https://www.meetup.com/pro/wordpress/
Keep checking back every week to find out what else is going on!
Donations from across the galaxy!
Producership Credits are a thing that do actually exist – we offer them up to those who donate through Time, Talent or Treasure. You can use these credits to boost up your resume, add to your LinkedIn file, so on and so forth!
Even if you are not interested in receiving a Producership Credit, check out how you can use us as your own stepping ladder in the world of the internets – get yourself an interview, get us to make your announcement for you, let the world know you have something to say or a company worth checking out!
Have a look through our site wppluginsatoz.com. Check out the Time, Talent and Treasure pages.
Today’s Plugins we covered were:
John’s Plugin:
Shipping Live Rates for Canada Post for WooCommerce By octolize
- Displays the Canada post live rates
- Automatic shipping cost calculation based on the live rates
- Domestic and international Canad Post services
Rating: 5 Dragons
Amber’s Plugin:
Bot Lockout By kognetiks
- Lightweight protection
- Multi-site support (apply settings to all sites in the network)
- uses JavaScript-based cryptographic operations that are easy for humans but difficult for most bots to solve.
Rating: 5 Dragon
How to reach us:
Feel like sending us something through the snail mail system? You can do that thanks to our brick and mortar address that we provide for you!
You can also reach us the more common way of the internets – have both of our internets available down below for ya!
WP Plugins A to Z
C/O John Overall
20-754 E Fairview Rd.
Victoria, BC V9A 5T9
Canada
John:
- My website: http://www.johnoverall.com/
- WordPress Emergency Support: http://wppro.ca/wpemergency
- email: john@wppro.ca
Amber:
- email: amber@wppro.ca
Q & A Time with Amber – Catch this info on our YouTube Channel
If you have questions you would like to have asked on the show, send them in to me at Amber@WPPro.ca – we may never stump my dad, but we can get some good conversation out of him at least!
- Do you know why JavaScript is so hard for bots to solve?
- What exactly is multi site support – is it where you just download the same plugin over and over and set it up the same way?
- If so, why is that important to note on plugin information for people?
Questions asked after closing credits:
- I have noticed that people are using odder and odder platforms for socials. Do you think that the socials are morphing again, or are they simply expanding and we have more choices?
- How long does it take for one kind of platform to fade away and be fully replaced by another?
- Do you think the time line will be any different today then it was in the past?
- Why or why not?
- Do you think the time line will be any different today then it was in the past?