Podcast: Play in new window | Download | Embed
Good morning, good afternoon, good evening ………. I’m your host, John Overall— welcome to Episode 22 of Plugin Pulse: “Hardening WordPress Before the Next Headline Hits.” It’s … WP Plugins A to Z Unplugged!, and today we’re wading straight into the the muck.
So Grab your coffee, fire up the dashboard, and let’s get into it — unplugged, unfiltered, and straight from the source. We are not waiting for the breach post today. We are talking about the staging copy that still emails real customers and can charge a real card, the court filings that show WordPress.org charting ACF Pro installs it does not host, the analytics dashboard that only counts a visit if it became a lead, the malware that rewrites itself after you delete the files, the site that found two webshells and five admins nobody created, and Cloudflare filing to become a certificate authority before it has issued a single certificate. Plus a little something in the war against scumbag lawyers. Harden it now. The headline can wait. Let’s get into it.
Remember you can Join me Live on Show-days, every second Friday at 12 pm PDT by going to https://wppluginsatoz.com/live and clicking the link to this shows Google Meet Link which goes live at showtime.
If you’re listening to me on YouTube, remember to like and hit the bell to subscribe and get a reminder of when I am here.
You can also join me Sundays at 7PST on Tavern Talk at the Rogues Oasis — where the fire crackles, the ale flows, and straight talk cuts through the night like a rogue’s blade at the Devil’s Crossroad.
We’re back, friends — raw, unfiltered conversations rooted in the wild trails of Vancouver Island and the timeless fight for self-reliance. From homesteading grit and pantry wisdom to the inner wilderness of faith, soul, and everyday storms, we pull up a stool with real talk that arms you for the days ahead.
Live to tape every Sunday ay 7pm PDT
Pull up a chair, grab your mug, and join the fellowship. The door’s open — let’s talk truth.
The Weeks Discussions:
TLDR Summery:
Rodolfo Melogli asked a simple question on 29 September 2026, and the answers are the topic. He runs Business Bloomer, writes WooCommerce snippets for a living, and we sat down with him in Interview 78 on mini-plugins, summits, and how that community actually works. This post is the same builder, smaller job. He is not talking about a new exploit. He is talking about the staging copy that still behaves like production. The question is here: https://x.com/rmelogli/status/2104855760328872346. He is building a free plugin that is meant to make a staging copy safe the moment you activate it. He has not named it. On 30 September he said it is launching soon, and he was already ticking items off the replies as he built. His own list is the short version of every staging horror story. A test order emails a real customer. Live Stripe or PayPal keys are still in the copy, so a test checkout can charge a real card. Subscription renewals copied from the live store run again on staging. Webhooks push fake orders into the fulfillment or accounting app. Two identical dashboards in two browser tabs, and you are never sure which one is live. That last one is the human failure. The first four are the machine doing exactly what it was told.
The replies filled the gaps he had not written down. Katie Keith said the email one in a single line. Marco Almeida’s was worse: he deleted subscriptions on staging and Stripe cancelled the authorizations on its side. Renewals on the production store died. He said it took out 30-plus subscriptions on his own site. Manish Mohan flagged Meta and Google Site Kit still pointing at the live property, so staging traffic lands in the real ads and analytics accounts. Migro, the content-migration plugin, said they were taking notes. They already leave price and stock alone when pushing content from staging to production. Rodolfo answered in the thread, not in a changelog. Emails stop by default, with an option to redirect everything to one address when you are testing copy. If a plugin replaces wp_mail(), the status bar flags an email-bypass risk. Subscription orders and the subscription post type are locked so they cannot be deleted on the copy. The next day he opened the question to anyone who runs a WordPress site, not just a store: https://x.com/rmelogli/status/2105259161906786542. Katie came back with the search-engine box. Someone copies staging to live and forgets to untick “Discourage search engines.” Serafin described an HPOS sync that wrote full duplicates into both the legacy tables and the new ones. Jonathan de Jong’s shop ran a batch job against tens of thousands of users with an SMTP plugin still active, and the same people got the email more than once. His team now disables the common SMTP plugins on staging by default. That is the other half of hardening. The next headline does not have to be a zero-day. It can be a cloned database, a live API key, and a cron that still thinks it is production. Hosting clones do not cut those wires. A lot of staging plugins only change the URL.
End summery<<
Full notes:
Rodolfo Melogli asked the WooCommerce crowd a simple question on 29 September 2026, and the answers are the real topic. He is not talking about a new exploit. He is talking about the staging copy that still behaves like production.
What’s the worst thing that ever happened to you on a WooCommerce staging site?What’s the worst thing that ever happened to you on a WooCommerce staging site?
The post is here: https://x.com/rmelogli/status/2104855760328872346. Rodolfo runs Business Bloomer, writes WooCommerce snippets for a living, and is building a free plugin that is meant to make a staging copy safe the moment you activate it. He has not named it. On 30 September he said it is launching soon, and he was already ticking items off the reply thread as he built. His own list is the short version of every staging horror story:
A test order sends a real email to a real customer. Live Stripe or PayPal keys are still in the copy, so a test checkout can charge a real card. Subscription renewals copied from the live store run again on staging. Webhooks push fake orders into the fulfillment or accounting app. Two identical dashboards in two browser tabs, and you are never sure which one is live.
That last one is the human failure. The first four are the machine doing exactly what it was told. The replies filled in the gaps he had not written down.
Katie Keith’s answer was the email one. Same failure, said in one line. Marco Almeida’s was worse: he deleted subscriptions on staging and Stripe cancelled the authorizations on its side. Renewals on the production store died. He said it took out 30-plus subscriptions on his own site. Manish Mohan flagged Meta and Google Site Kit still pointing at the live property, so staging traffic and test events land in the real ads and analytics accounts. Migro, the content-migration plugin, replied that they were taking notes. They already leave price and stock alone when pushing content staging to production, and they may tighten that further.
Rodolfo answered in the thread, not in a changelog. Emails stop by default, with an option to redirect everything to one address when you are actually testing email copy. If a plugin replaces wp_mail(), the status bar flags an email-bypass risk. Subscription orders and the subscription post type are locked so they cannot be deleted on the staging copy. Marco’s point was the prompt for that lock. Plugins that send mail outside wp_mail() are the hole in the email block, and he said so himself.
The next day he widened the question to anyone who builds or runs WordPress sites, not just WooCommerce stores: https://x.com/rmelogli/status/2105259161906786542. Katie came back with the search-engine box. Someone copies staging to live and forgets to untick “Discourage search engines.” Serafin described a WooCommerce update where HPOS sync wrote full duplicates into both the legacy tables and the HPOS tables. Jonathan de Jong’s shop ran a batch job against tens of thousands of users, an SMTP plugin was still active, and the same people got the email more than once. His team now has a script that disables the common SMTP plugins on staging by default. That is the show angle. Hardening is usually framed as login limits, 2FA, and file permissions. This thread is the other half. The next headline does not have to be a zero-day. It can be a cloned database, a live API key, and a cron that still thinks it is production. Staging is not a safe room until you cut the wires: mail, payments, webhooks, subscriptions, analytics, search indexing. Hosting clones do not do that for you. A lot of “staging” plugins only change the URL.
Things to think about:
For our listeners listeners what are their own staging scar. The thread is still thin. Eight likes, about 1,900 views, ten replies. The useful ones are specific. The Stripe subscription case is the one to dwell on. Deleting a record on a copy can cancel a live billing agreement. That is not a WordPress bug. It is a shared secret that survived the clone. Email redirect is the easy win. Payment-key stripping and webhook killing are the ones people skip because the store “looks fine.” Jonathan’s SMTP auto-disable is the practical version of what Rodolfo is productizing. Agencies already script this. Most site owners do not. Do not name the plugin. He has not shipped a name. “Launching soon” is the status as of 30 September.
Source posts: the original question, Rodolfo’s implementation replies in that thread, and the 30 September follow-up that opened it to all of WordPress.
Check out the interview with Rodolfo here https://wppluginsatoz.com/interview-78-woocommerce-wizardry-rodolfo-melogli-on-mini-plugins-summits-and-community-secrets/
WordPress Drama:
The WPE v WP drama continues
The new piece is not a fresh fight. It is old testimony that just became public. Rae Morey at The Repository published it on 1 October 2026, off deposition excerpts unsealed the day before in WP Engine’s case against Automattic and Matt Mullenweg. The X post is the headline only: https://x.com/therepositorywp/status/2105660813545533575. The piece is here: https://www.therepository.email/court-filings-reveal-wordpress-orgs-mission-control-dashboard-tracked-wp-engines-acf-pro-installs.
Two facts carry the segment.
First, WordPress.org has a password-protected dashboard called Mission Control, at mc.wordpress.org. Automattic CTO Barry Abrahamson described it in deposition as a dashboard that shows statistics about WordPress.org. The data comes from sites checking WordPress.org for plugin and theme updates, every 12 hours by default. A script anonymizes it, aggregates it, and stores it in a database he thought might be called Stats. WP Engine’s lawyers showed him printouts from that dashboard graphing active installs of ACF Pro over time. ACF Pro is not in the WordPress.org directory. It is sold from advancedcustomfields.com. The free ACF plugin is the one WordPress.org hosts. Automattic’s lawyer objected that the ACF Pro questions were outside the scope of Abrahamson’s testimony. The printouts were still in the record.
That is the sharp edge. WordPress.org does not distribute ACF Pro, and a private .org dashboard was still charting how many active installs it knew about. The mechanism is the update check, not a login to the ACF site. Any site that phones home to WordPress.org for updates can report which plugins are present, including premium ones WordPress.org does not host. Abrahamson’s account is that the data is anonymized and aggregated. The filing does not say they were tracking named customers.
Second, Matt wrote this in Slack to Jesse Friedman on 15 August 2024, before the dispute went public: “It’s feeling like we’re about to go full nuclear with WPE, with a possibility of a partnerships/merger/M&A as an exit, but in general there will be a realignment.” In deposition he said he did not recall writing it and did not know what “full nuclear” meant without the full context. Magistrate Judge Ajay Krishnan later ruled the 21-hour deposition evasive and gave WP Engine three more hours. A redacted stretch of the same transcript covers confidential trademark licensing strategy.
The rest of the filing is schedule and counsel, not new allegations. Gibson Dunn withdrew in September over a conflict. Automattic hired Susman Godfrey. The new lawyers want expert discovery pushed from 17 November 2026 to 14 January 2027, and summary judgment motions from 20 November to 19 January 2027. Trial is still set for 19 October 2027. WP Engine called the extension a non-starter. The court hears WP Engine’s sanctions motion on 7 October. Expert lists are long: 12 on the Automattic side, including Abrahamson, Anne McCarthy, and licensing lawyer Heather Meeker; 10 on the WP Engine side, including Harvard’s Paul Gompers and Philip Hackney.
Context if you need one line of history. This case is two years old. In October 2024 WordPress.org took the free ACF slug. A month later it forked ACF Pro. A preliminary injunction forced Automattic to drop the checkbox asking if a site was affiliated with WP Engine. The replacement checkbox asks if pineapple is delicious on pizza. Matt has said he will take credit for that one. On 25 September 2026 Judge Araceli Martínez-Olguín put WP Engine’s antitrust claims back on the table after dismissing them in 2025.
Talking points:
-
Mission Control is the line people will repeat. A private .org stats board charting a plugin .org does not host.
-
Do not upgrade that to “they tracked WP Engine customers.” The testimony in the piece is active-install graphs from update checks, anonymized and aggregated. The customer-list version is not what Abrahamson described.
-
The Slack line is the other clip. “Full nuclear,” with merger or M&A as an exit, written a month before the public break.
-
The 7 October sanctions hearing is the next date. The trial is still a year out.
Some SEO Stuff:
Some SEO Help
TLDR Summery:
This one is analytics, not rankings. Derek Ashauer posted it on 1 October 2026 from the Conversion Bridge account: most WordPress dashboards show sessions, pageviews, and bounce rate, and none of those tell you whether a visit turned into anything. The write-up is https://conversionbridgewp.com/wordpress-analytics-dashboard/. The post is https://x.com/ConversionWP/status/2105674129210769744. The page went up on 11 September and was updated on 14 September, the same day Conversion Bridge 1.16 shipped a rebuilt Google Analytics dashboard. Derek builds the plugin. Its job is to send conversion events from WordPress plugins into analytics and ad platforms. The dashboard is the view: traffic and conversions inside wp-admin, so a site owner does not have to open GA4, pick the property, and set the date range every time they want a number. His case against GA4 is the interface, not the data. It is free, and most owners want to keep it. The UI is built around explorations and events, and a lot of clients never open it. Privacy tools such as Plausible, Fathom, Pirsch, Umami, and PostHog already have simple boards you can embed. Google does not. Conversion Bridge pulls GA4 through the API and lays out its own page. He is clear that this is a view, not a replacement. You still have to set GA4 up. Advanced marketers still use Google’s own reports.
What the board shows is the usual top line, then the part he actually cares about. Sessions, users, pageviews, bounce rate, and visit length over time. Under that, a conversion events table with count, rate, revenue, and change against the previous period. Then sources, pages, locations, devices, an activity heatmap, and recent conversions. The filter is the feature. Pick purchases, or form leads, and the rest of the board narrows to the people who did that. Sources become the sources that produced buyers. Pages become the pages buyers looked at. Role permissions decide who sees the Analytics menu, so a client can look without an administrator account. The conversion numbers come from tracking the plugin already does. The page says it connects 71 WordPress plugins, so form submissions, purchases, signups, and bookings land as events without custom code. Version 1.16 also added linked journeys: turn it on and a user profile can list the paths that person took before they converted. It can embed boards from Plausible, Fathom, Pirsch, Umami Cloud, PostHog, Swetrix, GoSquared, Usermaven, and Microsoft Clarity. The GA4 board is the one it has to build itself. Pricing is not on this page. There is an agency partner program with a free license to try it on your own site. Treat the post as a product pitch. One like, one repost, 19 views. SEO help here means “did the traffic do anything,” not titles and schema. A lot of retainers die because the client never opens GA4 and cannot see the leads. Do not let it slide into “ditch Google Analytics.” His own copy says the dashboard is a view, and GA4 is still the source. The line worth stealing, even if nobody buys the plugin, is the filter. A traffic report that cannot collapse to buyers is a vanity report.
End summery<<
Show Notes:
This one is analytics, not rankings. Derek Ashauer posted it on 1 October 2026 from the Conversion Bridge account: most WordPress analytics dashboards show sessions, pageviews, and bounce rate, and none of those tell you whether a visit turned into anything. The write-up is https://conversionbridgewp.com/wordpress-analytics-dashboard/. The post is https://x.com/ConversionWP/status/2105674129210769744. The page itself went up on 11 September and was updated on 14 September, the same day Conversion Bridge 1.16 shipped a rebuilt Google Analytics dashboard.
Derek builds Conversion Bridge. The plugin’s job is to send conversion events from WordPress plugins into analytics and ad platforms. The dashboard piece is the view: traffic and conversions inside wp-admin, so a site owner does not have to open GA4, pick the property, and set the date range every time they want a number.
His case against GA4 is the interface, not the data. GA4 is free and most owners want to keep it. The UI is built around explorations and events, and a lot of clients never open it. Privacy tools such as Plausible, Fathom, Pirsch, Umami, and PostHog already have simple dashboards you can embed. Google does not. Conversion Bridge pulls GA4 through the API and lays out its own page. He is clear that this is a view of GA4, not a replacement. You still have to set GA4 up. Advanced marketers still use Google’s own reports.
What the dashboard shows is the usual top line, then the part he actually cares about. Sessions, users, pageviews, bounce rate, and visit length over time. Under that, a conversion events table with count, rate, revenue, and change against the previous period. Then sources, pages, locations, devices, an activity heatmap, and recent conversions. The filter is the feature he highlights. Pick purchases, or form leads, and the rest of the board narrows to the people who did that. Sources become the sources that produced buyers. Pages become the pages buyers looked at. Role permissions decide who sees the Analytics menu, so a client can look without an administrator account.
The conversion numbers come from tracking the plugin already does. The page says it connects 71 WordPress plugins, so form submissions, purchases, signups, and bookings land as events without custom code. Version 1.16 also added linked journeys: turn it on and a user profile can list the paths that person took before they converted. It can embed dashboards from Plausible, Fathom, Pirsch, Umami Cloud, PostHog, Swetrix, GoSquared, Usermaven, and Microsoft Clarity. The GA4 board is the one it has to build itself.
Pricing is not on this page. There is an agency partner program with a free license to try it on your own site. Treat the post as a product pitch. The engagement was tiny: one like, one repost, 19 views.
Show angle, if you want it next to hardening:
-
SEO help here means “did the traffic do anything,” not titles and schema. Sessions without a conversion event are a vanity report.
-
The client-login problem is real. A lot of retainers die because the client never opens GA4 and cannot see the leads.
-
Do not let it slide into “ditch Google Analytics.” His own copy says the dashboard is a view, and GA4 is still the source.
-
The filter-by-conversion idea is the line worth stealing even if nobody buys the plugin. Traffic reports should be able to collapse to buyers only.
V for V for the show
Make mention here about the “Revival of The Tavern at the Oasis” Podcast fid the episodes here https://theroguesoasis.com/tavern-talk-podcast-show/ or find us in your favourite podcast app.
If you get any value out of this show then donate that value back to the show. You can do so through time, talent, or treasure – or all 3!! – through our website wppluginsatoz.com.
Click on the ‘Treasure Donations’ link on the left-hand menu, or on the ‘Time, or Talent‘ pages to find out more!
Sign up for newsletter https://wppluginsatoz.com/news
Security Stuff:
Self healing Malware
Summery:
A manual file cleanup is not a clean anymore. On 22 September a site owner on r/Wordpress wrote up a self-healing infection that came back within 24 hours after they deleted the bad PHP. Visitors were seeing a fake Cloudflare “Verify you are human” box, the ClickFix lure that tries to get someone to paste a command from the clipboard.
The files were the symptom. The source of truth was in the database, stored as site-health transients, and in boot code in wp-config.php or object-cache.php that rewrote the plugin on the next page load. Hourly cron did the same job. The must-use plugins had ordinary names: wp-own-assets, wp-feed-normalize, wp-rest-cache, wp-rest-hardening, wp-rest-optimizer. Those do not show up in the normal plugins screen.
Same family of problem as the SC reports from September, different field report. If it returns on the next page load, you did not get the thing that writes the files back.
https://www.reddit.com/r/Wordpress/comments/1wnaydr/selfhealing_wordpress_malware_survived_a_manual/
This is a site-owner cleanup report, not a vendor write-up. It went up on r/Wordpress on 22 September 2026: Self-healing WordPress malware survived a manual cleanup. The poster said they had just cleaned a couple of WordPress sites, they were not dropping payloads or backdoor keys, and a manual file cleanup was not enough. It came back within 24 hours because the source of truth was in the database and in wp-config.php.
What visitors saw was a fake Cloudflare “Verify you are human” overlay. That is the ClickFix pattern. The interaction tries to get the person to paste a command from the clipboard. The site is the lure. The damage they are after is on the visitor’s machine, not only in the WordPress files.
The persistence they describe is three layers that restore each other.
-
Database. Base64 payloads stored in wp_options as transients named like _site_transient_health_*.
-
Files. Fake plugins, must-use plugins, copies under wp-includes/assets/, and sometimes uploads/.
-
Boot code. Restore logic in wp-config.php and/or wp-content/object-cache.php that rewrote the plugin from the database on every request, plus hourly cron hooks.
Delete only the PHP files and the next page load recreates them. That is the whole lesson of the post.
The filenames they tell people to hunt are must-use plugins with ordinary-looking names: wp-own-assets.php, and variants of wp-feed-normalize, wp-rest-cache, wp-rest-hardening, and wp-rest-optimizer. Those sit in wp-content/mu-plugins/, which loads automatically and does not show up in the normal plugins screen. The rest of the post is a hunt list. I am not turning that into a removal recipe here. The public point is the shape of it: health-check transient names, drop-in files, and cron.
Do not fold this into the episode 21 segment without saying they are related but not the same report. Episode 21 was the SC family write-ups: Konstantinos Bourdakos on 8 September (15 persistence layers, database as the payload, 1,200-plus sites in his count) and the Sucuri SC mesh that the trade press picked up again on 1 October, with copies in files, the database, and shared memory, plus an Ethereum command channel. This Reddit post is a smaller field report from 22 September. Same idea, different evidence. ClickFix overlay, those specific mu-plugin names, transients dressed up as site-health data, and a restore stub in wp-config.php or object-cache.php.
Talking points:
-
“We cleaned the files” is not a clean. If it returns in a day, or on the next page load, the payload is still in the database, a drop-in, or cron.
-
Must-use plugins and drop-ins are the blind spot. They do not appear in the plugins list the way a normal install does.
-
The visitor-facing symptom is the fake Cloudflare check. That is worth saying out loud so people do not treat a “verify you are human” box on a WordPress site as a hosting glitch.
-
The fix on air is the boring one. Stop the thing that writes the files back, then rebuild core, plugins, and theme from known-good copies. A file-only delete is how this one survived.
Looking at web shells
Someone found two webshells and five administrator accounts they did not create. A webshell is a script left on the server so the attacker can come back without logging into wp-admin. The fake admins are the other door. Delete the files and leave the users, and they are still in. Delete the users and leave the shell, and the next request can create the users again. Five accounts is not a typo. One hidden admin is the usual find. Five means they were not worried about being noticed, or they were replacing accounts as fast as they were deleted.
That is the hardening line. Users you do not recognize are not a cleanup item for later. They are the same incident as the files.
Cloud flare to become a CA auth https://blog.cloudflare.com/cloudflare-certificate-authority/
Cloudflare is not a certificate authority yet. On 29 September 2026 Steve Goldsmith posted the intent: Building a certificate authority for the whole Internet. They have applied for the Chrome, Apple, Microsoft, and Mozilla root programs, and they have a definitive agreement to buy an established GlobalSign root so the certificates are trusted on day one. That root has been in devices since 2012. A brand-new root would take years to reach phones and browsers that never update. They are not issuing certificates yet, and the post says it will be a while before they do.
The pitch is redundancy, not a replacement for Let’s Encrypt. Cloudflare is already one of the largest buyers of public certificates. Universal SSL, the free padlock on sites proxied through them, is issued by other CAs. Goldsmith’s line is that a free automated CA with backups is the same argument as Universal SSL, moved down one layer. If the dominant issuer has a bad day, the encrypted web should not have a single point of failure. They say they will keep working with partner CAs. The trade write-ups are calling it a rival to Let’s Encrypt. The blog does not.
Issuance will be free and automated over ACME, the same protocol Let’s Encrypt, Google Trust Services, and SSL.com already use. No new toolchain if a host already speaks ACME. The condition is ACME Renewal Information, RFC 9773. The client has to poll for the renewal window instead of guessing. A signup for updates is at cloudflare.com/resource/certificate-authority.
The second announcement, same day, is the one with a date. They want to be an early issuer of Merkle Tree Certificates, the compact format Chrome is lining up for post-quantum authentication. First production MTCs are targeted for the first quarter of 2027, free, aimed at Chrome’s Quantum-resistant Root Program. Classic certificates stay. There is no cutover.
For a WordPress site this changes nothing this month. A host that already gets Let’s Encrypt for you does not need to switch. A site already on Cloudflare already has Universal SSL from someone else. The useful line on air is the trust layer, not a plugin. The padlock on most sites is rented. Cloudflare wants to be one of the landlords, with an old GlobalSign root for reach and a new root for the long run. Until they actually issue, it is a filing and a purchase agreement.
Privacy Stuff:
Big CIPA win in Cali https://x.com/termageddon/status/2105658999081476522
Termageddon called it a big one on 1 October 2026, and the bill is already law. The post is https://x.com/termageddon/status/2105658999081476522. Certain attorneys have spent the last several years sending demand letters to businesses across the U.S. for California Invasion of Privacy Act violations. The letters, in Termageddon’s telling, came down to “pay us $50,000, or we’ll take you to court.” CIPA is a 1960s wiretap law written for landline pen registers. Plaintiffs reused the pen-register and trap-and-trace section against ordinary website tools: Google Analytics, a Meta pixel, a chat widget, anything that phones a third party. Statutory damages are $5,000 a violation, so a class claim scales fast. Reuters reported on 1 October that Governor Gavin Newsom signed Senate Bill 690 the day before. His note to the Senate said it “addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses.” Fisher Phillips has counted more than 4,700 digital-wiretapping suits since 2022 that were filed in California or invoked California law. About two-thirds included a pen-register claim. That count does not include the demand letters. Forbes settled one of these class actions for $10 million. The Los Angeles Times settled another for $3.85 million.
The change is narrower than the first draft. SB 690 strips the private right of action from the pen-register provision. It takes effect 1 January 2027, and it applies backward to claims brought in the past two years. An earlier version would have exempted tracking that served a “commercial business purpose” across several CIPA sections. That language was cut. Plaintiffs can still sue under other California and federal privacy laws. A consent banner is still the practical control if a California visitor hits a site running third-party scripts. Termageddon sells the policy and the banner, so read the post as a vendor marking a win it has been warning about. The show line is the letter, not the product. A WordPress site with Analytics and a pixel was being treated like a phone tap, and the state just took the private lawsuit off that one section.
This Shows Featured Promotion
Every show I will be promoting a premium plugin or service I think might be useful for everyone. There is no affiliate links to them unless mentioned. This is just to bring more attention to underknown premium plugins or services that I believe can be of benefit.
This week the Feature is:
Toggle WP
The Lowdown:
How ToggleWP Helps
-
On-Brand AI Upsells: Deploy a high-end AI writing assistant directly in the client dashboard, allowing you to charge a premium for “AI-Enhanced” maintenance tiers.
-
Zero-Cost Fulfillment (BYOK): Use your own API key to provide advanced content tools with no monthly markup, keeping 100% of the profit from your client subscriptions.
-
Done-With-You Content: Reduce the time spent drafting blogs or social snippets for clients by 80%, increasing your hourly effective rate.
-
Feature Lock-In: Create a “sticky” workspace that makes it nearly impossible for clients to leave your care for a budget host that lacks these tools.
The Maintenance-Focused Freelancer
How ToggleWP Helps
-
Plugin Control: Hide essential plugins from client admins (so they can’t accidentally deactivate your security or backup plugins, or enable auto updates)
-
Plugin Activation / Deactivation Notifications: Get instant alerts when clients make plugin changes
-
SEO Warnings: Visual warnings prevent “oops” moments like blocking indexing on a production site
-
Staging Site Warning: Remind clients not to update live site content while you are working on staging with notices on the login screen / after login
-
Reminders: Track renewal dates for domains, annual subscriptions or premium licenses with email notifications before expiry
The Boutique Hosting Provider
How ToggleWP Helps
-
Login Monitoring: Track admin logins with IP/country detection, spot suspicious access patterns across your portfolio
-
Admin Notifications: Automated email system sends you monthly last login reports and instant alerts for unusual logins
-
Session Management: Force logout inactive sessions, limit admin user sessions to 1 hour
-
Media Management: Clients can organise their media uploads with custom categories and tags, allowing easy filtering from the Insert Media screen
-
Reminders: Track renewal dates for domains, annual subscriptions or premium licenses with email notifications before expiry
Tip of The Day:
Satirical game on the realities of running a plugin business [FREE]
Link straight to the Game https://pressword.games/games/install-clicker/
Warning it mildly addictive…
Pet Peeve This Week Or WP drama:
Lets talk about the new Kujo will this go well hasn’t anyone even read the book or seen the movie?
Upcoming Interviews and Available times:
Reminder that we have no more interviews coming up but you can check out the past ones here https://wppluginsatoz.com/book-an-interview-on-wp-plugins-a-to-z-podcast/
Upcoming Interviews: None
Available interview dates: None.
Other Shows and places to get WP Info & Training
The WP Builds Podcast
WP Roads
WP-Tonic
Worlds Worst Web Developer
WP Mayor
wp Minute
The WP Week newsletter
Kitchensink WP





