2023 Recaps & 2024 Security Concerns

If you’re serious about building better WordPress sites, this is the newsletter for you.

I hope you had a wonderful holiday season and New Year’s. I certainly did. Lots of downtime, family time, and way too much food. Just like it’s supposed to be.

While some of you have having a quiet few weeks, others have been very productive already, so welcome to a very full 101th edition of Inside WordPress!

Let’s jump right in, shall we?

Want to get in front of a 1040+ dedicated WordPress friends? Check out ​my sponsoring options​ and reach out to me if you think we can be a good fit!

🗞️ Inside WordPress News

Here’s what I saw happening this past week:

Very good read. I think you should read it. Regardless of whether you’re a WordPress plugin developer or not.


Love neat tools like this! And the ​social image generating plugin page​ where he’s hosting this tool itself is pretty cool, too.


There’s a lot to be optimized in this code example, but this is a great demonstration of how to use AI in a manner where it truly makes sense.


  • ​Advanced Query Loop​ by Ryan Welcher is one of my personal favorite plugins that enhances a default Block. Ryan recently updated it so now ACF users will see their meta keys in the auto-complete list for Post Meta queries!

  • WordPress as a game development platform. Not your usual application, but Jonathan Bossenger took that idea to heart and created exactly that. And ​you get to play with it​! See if you can push yourself onto that leaderboard.


Four year recaps to learn from:

  1. ​Barn2​
  2. ​Studio Woombat​
  3. ​Freemius​
  4. ​Ajay D’Souza​

All four most excellent reads. And I’d be surprised if you didn’t learn anything from either one of those.


🚀 Performance

My favorite performance optimizing tools in WordPress:


🔆 Inside WordPress Highlight

The Real Attack Vector Responsible for 60% of Hacked WordPress Sites in 2023.

Yeah, that sentence should indeed grab your attention. We Watch Your Website plublished an incredibly in-depth article with exactly that title.

Let me repeat: 60% of WordPress sites are hacked through session hijacking. Exploited Plugin/Theme Vulnerabilities are distant second. The mean sample size: 6m sites and 851 billion data points analyzed. That’s insane. I had ​Calvin Alkan on my podcast​ at the end of last year and asked for a quote on this, as he is a security specialist over at ​Fortress​ , and this is what he had anything to say:

I can only see this trend rising as more and more sites adopt 2FA and because almost nobody in the ecosystem has any protection against it.

So where I was hoping for some, I dunno, something positive… he’s actually doubling down on the severity of the trend. In other words, ​read the research and act accordingly​.

Some of my favorite WordPress tools:


💡 Interesting Finds

  • Did you know there’s an overview of meetups and WordCamps nowadays? Bookmark this URL and let 2024 be all about the revival of meeting up over WordPress: ​https://events.wordpress.org/​


🎁 Bonus

​Don’t use in-app web browsers​ if you care about keeping your passwords private: “Meta injects special “keylogging” JavaScript onto the website you’re visiting that allows the company to monitor everything you type and tap on, including passwords.”


That’s it for this week’s edition of Inside WordPress. Thanks for reading!

Join the Within WordPress Newsletter Today

Get on top of valuable WordPress news, tools, and techniques—and join more than 2000+ today!

This field is for validation purposes and should be left unchanged.
First name


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *