Reading view

How do you handle bot traffic when you can’t geo-block?

Just wrapped up a project migrating a client's mid-size ecommerce store off Shopify to self-hosted WooCommerce, age-restricted products so compliance was heavy, on managed hosting with Cloudflare Enterprise through the host. Ran into a solid bot traffic problem during the process and wanted to share what I did, plus ask you all a question since my fix only works because the client is US-only.

The site started getting 503s during traffic spikes. Turned out PHP-FPM workers were getting exhausted from bot traffic hammering the site. Didn't help that the caching plugin the host had installed by default had a broken cookie exclusion rule, so way more pages were loading fresh instead of from cache. That piled onto the bot load, but the bots were the real driver.

What I did about it:

- Ditched the host's default caching plugin, switched to WP Rocket, set up preload and a longer cache lifespan. Fixed the cache bypass issue.
- Geo-blocked all non-US traffic at the edge since the client only ships domestically anyway, with Google and Bing whitelisted so SEO wasn't affected. This alone wiped out most of the international bot traffic.
- Added rate limiting on the busiest pages, again with search engines excluded.
- Blocked xmlrpc.php at the server level instead of using a plugin for it.
- Turned on 2FA for all admin accounts plus a login attempt limiter.
- Switched WP cron to a real server-side scheduled task instead of the default.

Funny side effect, the geo-block also caught PageSpeed Insights and GTmetrix checks since those run from servers outside the US. Sorting out whitelisting for that now.

So here's my question: geo-blocking basically solved this since the client doesn't ship outside the US, but what do you do when that's not an option? If you've worked on a store that ships internationally, how do you deal with bot traffic without being able to just block by region? Behavioral bot management, different rate limiting approach, something else entirely? Also happy to hear if you'd have done anything differently with the above.

submitted by /u/sokmalamt
[link] [comments]
  •  

[PROMO] I’ve been WordPressing since 2007, and just released my first open-source theme

https://preview.redd.it/2i0bd18tk0lh1.png?width=1280&format=png&auto=webp&s=a717e67e020cafdb3bb1a304992956a4e58f7db3

I’ve been building sites with WordPress since 2007 or so, but until now I had never released one of my themes publicly. Absolute 2026 has passed review and is now available from the WordPress.org Theme Directory.

It’s a native block theme with complete page patterns and smaller component patterns for building your own layouts. There’s no proprietary builder, custom Project post type, or theme-specific content system.

I’m posting to ask for reviews and suggestions for improvement. The theme is a 1:1 translation of the components and page structures from my portfolio, so I’m interested to see what other practical uses people might find for it — case studies, personal projects, small service-business sites, or TBD. If anyone feels like installing it and kicking the tires, I’d like to hear about bugs, friction, missing features, and suggestions for improvement.

————

If you’re interested in the lore behind the design:

I’ve been introducing AI-generated images and vibe coding into my workflow, with reactions ranging from neutrality to blistering hostility. The positives I hear are about speed and convenience, never quality. And especially never about interesting or exciting design.

So I took it upon myself to start with the most banal Claude-meets-Tailwind pablum I could find — the true design voice of 2026 — and see how far I needed to tweak the typography, color, and structure to reach a place outside the bounds of AI slop. I found what I consider a reasonable middle ground and used it for my portfolio site, then thought it would be fun to convert it into a native WordPress block theme.

And imperfect as it might be, it was fun. I hope other folks find something interesting or even useful in it. I mean, it’s open source, so go nuts.

————

Getting Started:
https://donschnitzius.com/absolute-2026/getting-started/

WordPress.org Theme Directory:
https://wordpress.org/themes/absolute-2026/

submitted by /u/don1138
[link] [comments]
  •  

What has changed in WordPress in the last 10 years?

I'm by no means an expert but around 10 years ago I hosted a WordPress site and I was changing the theme manually, I think I even set up an unsuccessful e commerce site for a few months at one point. Has much changed since then? Is there anything revolutionary that wasn't used in the past? I'm thinking of setting a website up to post content about my projects

submitted by /u/Adamstrad
[link] [comments]
  •  

Can I use an AI generated HTML prototype to rebuild a client's WordPress site?

Hello everyone,

I am a first time web developer and recently landed a client for SEO. The thing is they now want me to completely redesign their website. As far as I can tell, their current site is built on WordPress.

To get an idea I used ChatGPT to generate a prototype. It gave me a static HTML file and ngl it hits all the boxes theme, fonts and layout the client needs.

Since I have this HTML file my question is Can I use this AI blueprint to actually build and launch the live WordPress site?

If so what is the best way to do this using AI or page builders? (e.g., converting HTML to a WordPress theme or using AI tools inside WordPress?)

I wanna make sure I deliver a clean, functional site without getting in over my head on the backend side since I'm new to this.

submitted by /u/Funkymole165
[link] [comments]
  •  

Setting up a WordPress site for a writer — where should I start?

I'm building a new WordPress website for my writing project, Madeline Oona Writes, and I'm at the beginning of putting everything together.

I recently found a beautiful theme that I love (Vivre), but before I start installing plugins and filling the site with content, I want to build it thoughtfully from the beginning, especially from an SEO perspective.

I've heard that SEO should guide the site's structure rather than being something you try to add at the end, and that makes a lot of sense to me. So I'm wondering:

What should I establish first in terms of site structure and SEO?

Should I plan my pages, categories and content strategy before installing plugins?

Which SEO plugin would you recommend in 2026, and why?

What other plugins are genuinely worth having for a writer/author website?

What would you avoid installing?

Are there any common mistakes I should avoid when building a site from the ground up?

I'm mainly looking for advice on how to approach the setup strategically.

If you're a writer, author, blogger, or someone who builds WordPress sites, I'd especially love to hear how you approached your own site and what you wish you'd known when you were starting out.

I'm hoping to build something with room to grow, so I'd rather make thoughtful decisions now than have to restructure everything later.

Thank you! I'd really appreciate hearing from people who've been through this before.

submitted by /u/Lesbicadabra
[link] [comments]
  •  

[Review] The second 8 new WordPress.org plugins of August 2026

As always, I tested again 8 featured plugins from WordPress.org. The second batch of August.
Here is what I think;

Lineate - Poetry Blocks (4.9/5)
Adds a dedicated poetry block, including an image export function.
Does exactly one thing and does it really well, and the poem-to-image export is a nice touch.
I can't find much to complain about. Maybe the native core poetry block is enough for you, but if you are serious about poetry, this is a great plugin.

VovaBlocks - Marketing & Content Blocks for Gutenberg (4.6/5)
A block collection focused on marketing and content blocks.
Very intuitive, lots of options, and I like that you can toggle which blocks actually show up.
Not a lot of unique blocks though, and the better ones are locked behind pro. Solid and it works, just a little bit too little to offer right now.

Hafenstudios Ads - Ad Manager, AdSense & Banner Ads (4.5/5)
Manage AdSense, banner ads, and split tests.
Split testing is probably my favorite feature, the AdSense/AI integration is nice, and the HTML block gives you a lot of freedom.
The regular templates are limited, and I think you suppose to convert them into a HTML block, if you like to do more… Not super intuitive. Also there are a few missing convenient functions like media and date picker. Reviews also look a little sus, low downloads but a lot of 5 star ratings....idk.

Sense Forms (4.4/5)
Form builder with GDPR tools, analytics, and conditional logic.
Nice onboarding, tons of fields, solid privacy and tracking options, and conditional logic that most free form plugins skip.
Some style options are buggy, especially hover states, and performance could be better since styles and scripts load unconditionally.

VertiFeed - Vertical Media Gallery (4.3/5)
A TikTok-style vertical video gallery block.
Simple interface, no bloat, lightweight.
First load can take a while, in Firefox especially (probably a bug…), and there's no video filesize limit. Otherwise pretty solid.

UnoDock (4.0/5)
A mobile sticky nav bar with icon buttons.
Easy to use, 8 templates to start from.
Preview isn't accurate, some icons have the wrong size or color, and you can't style buttons individually. It's okay, but I think there are better options.

BellePopups (3.8/5)
Yet another popup builder, this time with 10 starter templates.
Easy to use and it has a built-in contrast checker.
Preview is tiny, options like the darken-image slider are limited, and you're stuck with predefined templates. Doesn't really offer anything the others don't, and it feels a bit AI generated.

eBook Crafter - Convert Posts to PDF eBooks, Ready to Print (3.4/5)
Turns your posts into downloadable PDF ebooks.
Nice use of the block editor, and it keeps multiple versions of the PDFs you create.
Messes with your normal editor styling, the PDF output looks very different from the editor, and it feels unfinished overall. I like the idea, but it needs more work.

See the full breakdown with all the details on YT:
https://youtu.be/oQWJRlMAToo

What do you think about this selection? Will you install any of those?

submitted by /u/finart_13
[link] [comments]
  •  

WordPress critical error

Hello everyone!

I’m having an issue with a WordPress website. The site suddenly started showing the following critical error:

Warning: require_once(/home/www/public/wp-admin/includes/plugin.php): Failed to open stream: Permission denied in /home/www/public/wp-settings.php on line 579

Fatal error: Uncaught Error: Failed opening required '/home/www/public/wp-admin/includes/plugin.php' (include_path='.:/usr/share/php') in /home/www/public/wp-settings.php:579 Stack trace: #0 /home/www/public/wp-config.php(111): require_once() #1 /home/www/public/wp-load.php(50): require_once('...') #2 /home/www/public/wp-blog-header.php(13): require_once('...') #3 /home/www/public/index.php(17): require('...') #4 {main} thrown in /home/www/public/wp-settings.php on line 579

Has anyone encountered this issue before?

Any advice would be greatly appreciated!

submitted by /u/GijgerNL
[link] [comments]
  •  

SEMrush alternatives?

Hi everyone,

I was trying to start the 7-day free trial of SEMrush, but I found out that they no longer accept virtual cards for the trial. Unfortunately, I only have virtual cards available, so I can't activate it.

It's a bit frustrating because I wanted to test SEMrush properly for keyword research and competitor analysis.

Does anyone know a good SEMrush alternative that is cheaper but still has a solid keyword database and competitor research features?

I need something close to SEMrush, mainly for keyword research, SERP analysis, and finding opportunities from competitors.

Thanks!

submitted by /u/AideNo9466
[link] [comments]
  •  

User Registration Form - Extra Fields won't show.

I am currently building a registration form on my site using the paid User Registration form from WPexperts. It connects to my WooCommerce store.

Idea being that i am using the default fields for the standard email, password etc - and using the "extra fields" for a) File Upload (For picture ID's) b) Checkbox for consent.

However, when i go to the registration page - it only shows the default form and won't load the Extra feilds despite the options enabled in the settings to show extra feilds at the registration page.

Default Form shortcode [wc-user-registration-page] correctly displays account fields and enabled billing fields, but no fields saved under Default Form → Extra Fields are rendered on registration despite “Display Extra Fields on Registration” being enabled. Tested with File, Checkbox and plain Text Field.

The Default Form shortcode works and responds to General Settings and Default Fields. Billing fields enable/disable correctly and updated labels appear on the front end. However, no fields created under Default Form → Extra Fields render on [wc-user-registration-page], even with “Display Extra Field"” enabled. Tested with File, Checkbox and simple Text Field, including on a plain Gutenberg page with no Elementor.

Any idea what could be the issue? - I have raised a ticket but it's been nearly 24 hours with no response and I need to get this done.

Thank you!

submitted by /u/iusman975
[link] [comments]
  •  

Low traffic, zero niche recognition in YMYL (finance/insurance), and near-zero AdSense impressions (Blocksy + Autoptimize setup)

I'm struggling with a multi-layered issue on my site oraultima.com and could really use some expert advice. My site focuses on a strict niche: insurance, mortgages, and banking (YMYL).

Here is my current setup and situation:

  • Platform: WordPress with Classic Editor (no heavy page builders).
  • Theme: Blocksy.
  • Plugins/Setup: I use WPCode to inject the global AdSense script in the header.
  • Status: No manual actions, no security issues, and clean green status in Google Search Console. The ads.txt file is properly configured and authorized.

My Auto Ads configuration in AdSense:

  • Overlay formats: Only "Anchor ads" are enabled (set to Bottom only). Vignettes and Side-rail ads are turned off.
  • In-page formats: "Banner ads" are enabled (with max ads per page set to 6, and options like "Find other ad placements on article pages" and "Optimize existing ads" checked).

What I've already done regarding Autoptimize: I've fine-tuned Autoptimize to prevent script conflicts with AdSense:

  1. JavaScript: Disabled "Aggregate JS" to stop Autoptimize from merging or delaying Google scripts. Added strict exclusions: /adsbygoogle/, /pagead/, /doubleclick/, google_service_ad.js, show_ads.js, pagead2.googlesyndication.com, adsbygoogle, pagead/js.
  2. CSS & HTML: Standard CSS/HTML optimizations are active (aggregation and inline CSS), which don't interfere with ads.
  3. Image Lazy-load: Active, but excluded adsbygoogle, googlesyndication, wp-post-image, and logo.webp.
  4. Extra options: Kept only safe options (remove emojis, query strings, combine Google Fonts), avoiding preconnect, preload, or async JS to prevent conflicts.

Despite all this, I am facing three massive roadblocks:

  1. AdSense Impressions / Coverage is broken: Even though I get page views, AdSense impressions are practically at zero or single digits (coverage is around 12%). Specifically, in recent articles the in-page banner ads do not show up at all—users only see the single bottom anchor ad. Do any of you experience this behavior with Auto Ads?
  2. Google won't recognize my true niche: I am trying to rank for banking, insurance, and mortgages, but Google completely ignores my site for these keywords. According to my Search Console data, Google only sends me impressions and clicks for unrelated public employment queries (like "arretrati contratto medici 2026" or "ultimissime contratto medici 2026"). Surely a few sporadic posts about public contracts shouldn't dictate my entire site's niche or block me from ranking in finance. My traffic has dropped, and Google treats the site like it has no authority in the YMYL space.
  3. Low overall traffic: Because of the lack of visibility in my core niche, traffic remains very low.

My questions to the community:

  • Could the Blocksy theme be conflicting with Google Auto Ads (preventing in-page banners from rendering while only showing the anchor ad)? Should I switch to manual ad units?
  • How can I signal to Google that Ora Ultima is dedicated to finance/insurance when Google keeps pigeonholing me into unrelated topics (like public contracts) and ignoring my core YMYL content?
  • Any advice on recovering traffic and fixing this abysmal ad delivery?

Thanks a lot in advance for any insights!

submitted by /u/Ora-Ultima2024
[link] [comments]
  •  

[PROMO] Security layer against WordPress vulnerability mess

https://preview.redd.it/rqvqhjqmxvkh1.png?width=2548&format=png&auto=webp&s=070804d56a907afaf4e8537399f8c0bd68efad94

Hey everyone,

With WordPress vulnerabilities being reported left and right, I wrote a simple solution called Camouflage. It disables WordPress/PHP access for public users and serves static HTML through the Apache web server using .htaccess rules.

The philosophy is simple, bad actors exploit vulnerable code in WordPress themes, plugins and even WordPress core. If we restrict public access to PHP, it becomes extremely challenging to exploit a website.

I noticed many people export static versions of their sites and host them on another server or CDN but that comes with maintenance issues.

Camouflage keeps things simple. It creates static versions of your pages, serves them directly through the web server (which also makes them fast) and disables public access to PHP. It automatically refreshes static pages whenever content is updated.

Logged in admins get a secret token installed in their browser. They can also download the token because it's what allows them to access the login page while PHP is blocked for public access.

Ajax and other dynamic requests are disabled by default. The plugin offers a Request Tracker that lets you track dynamic requests such as form submissions and Ajax calls. You can then allow specific requests and only those requests will be allowed to pass through.

I think this approach is pretty solid and offers a real solution instead of simply reporting vulnerabilities like other security plugins do.

The project is open source and available on github https://github.com/hamza-mairaj/camouflage. Feel free to report issues, and contributions are welcome.

submitted by /u/Cold_Opposite_5298
[link] [comments]
  •  

Help a noob: using Markdown to write in WP

Hello there,

I've been away from WP for about 10 years so I have very little clues about the Gutemberg editor, what it can do, and if I need additional plugins.

My need : I want to write in WP just like I write in Github

  • type raw markdown and it auto convert into HTML - real time preview would be nice
  • type code blocks between 3 backticks (```php [...] ```)and have it syntax highlighted

I already got that typing some markdown gets auto converted (typing ## generates and H2), how do I get the code hilite?

Bonus if I can skip the gutemberg entirely, I find the interface atrocious, something closer to a simple textarea like we have in Github comments would be nicer.

I've check a few markdown plugins but they are either not doing what I need, or disabled because "security issues"

Thanks a lot !

submitted by /u/ozh
[link] [comments]
  •  

Wordfence for WordPress on LiteSpeed may weaken PHP process protection site-wide - and Wordfence has known about it for at least a decade

I’ve been looking again at something that has bothered me about Wordfence for years.

Wordfence runs long-running PHP processes, especially its scanner. On LiteSpeed servers, those processes must not simply be terminated when the client connection disappears or certain connection timeouts are reached.

That part is perfectly reasonable. The problem is how Wordfence handles it. Wordfence recommends adding a rule like this to .htaccess:

RewriteRule .* - [E=noabort:1] 

or even:

SetEnv noabort 1 

The important part here is .*.

This does not protect only the Wordfence scanner. It applies noabort to every matching PHP request on the site.

LiteSpeed itself explicitly warns against applying noabort globally and recommends restricting it to the specific scripts or requests that actually require long-running execution.

And there is a very good reason for that.

noabort changes how LiteSpeed handles PHP processes when a connection disappears. Together with noconntimeout, a PHP process can continue running far beyond what many administrators would normally expect.

And before someone points at PHP's max_execution_time: on LiteSpeed/LSPHP that is not necessarily the hard process lifetime limit people assume it is.

I have tested this myself. (I am a LiteSpeed developer)

A request can reach its configured PHP execution time while the associated process continues running. The LiteSpeed-side mechanism that can impose a hard process-time limit is LSAPI_MAX_PROCESS_TIME.

You can observe the difference directly at process level. So the issue is not that Wordfence needs noabort. The issue is this:

Why does a security plugin remove a server-side process protection globally when only a small number of its own requests actually need that exception?

And there is another part of this story that I think matters even more:

This is not a newly discovered edge case. Wordfence has been aware of this issue for at least a decade.

I raised this problem directly with Wordfence years ago. LiteSpeed has also made clear for a long time that global noabort should be avoided when the exception can be restricted to the requests that actually require it.

Yet the broad configuration is still being recommended. That history is what makes this particularly difficult to understand. Software contains mistakes. Security software contains mistakes too. That is not the issue.

The issue is when a security vendor is made aware that its own configuration unnecessarily weakens a server-side protection, the server vendor explicitly warns against that same configuration, a technically straightforward way to scope the exception exists, and the unsafe recommendation remains in place for years.

At that point, this is no longer just an overlooked configuration detail. It is a consciously unaddressed security trade-off imposed on Wordfence users. And technically, the solution is not complicated.

With mod_rewrite, noabort can be enabled only for the exact Wordfence request that actually requires it.

Conceptually:

RewriteCond %{QUERY_STRING} ... RewriteRule ^wp-admin/admin-ajax\.php$ - [E=noabort:1,E=noconntimeout:1] 

instead of:

RewriteRule .* - [E=noabort:1] 

Same Wordfence functionality. Very different security boundary.

Millions of WordPress users install Wordfence specifically because they trust it to improve the security of their sites. A security plugin should not unnecessarily weaken process controls for unrelated PHP code just because one of its own components needs an exception. And if a security vendor has known about that problem for at least a decade and still does not fix it, users should at least have the option to fix it themselves.

submitted by /u/Good_Flight6250
[link] [comments]
  •  

Why did wordpress not give me an option for a username?

I created a wordpress account, and was not given a chance to add a username like I could previously, instead it used my email, which I don't like, but now I can't change that. I tried deleting my account and starting over, but it wouldn't let me do that either. I know I can change the username on the individual sites, but still, I do not like seeing my email as my username, it just feels personal, even if I'm the only one who can see it.

submitted by /u/illustratious
[link] [comments]
  •  

Need help with finding the right booking plugin

Hello everyone,

For years now I've been on the lookout for an appointment booking system that caters to my needs, but I have yet to find one that matches the features I'm looking for and has modern features. I thought I'd come here to ask for some help in the hopes that someone can point me in the right direction.

My work is quite simple, I'm an architectural designer and my clients book me to visit a different house everyday to measure and draw existing homes.

I am looking for the best booking plugin to allow my clients to book a date & time for their specified address. A lot of the appointment booking plugins I am seeing are for single locations, for instance barbershops, hotels, etc.

I am currently using a somewhat outdated plugin that doesn't seem to be around anymore or supported, called Booked by Boxy Studio. This was included in a Wordpress theme I purchased called "Entrepreneur"

Any help or guidance would be greatly appreciated!

Thank you.

submitted by /u/TheArshytect
[link] [comments]
  •  

Odd alignment issue after 2025 theme update

Gutenberg only - no page builders.
I have a backup, but would like to figure this out -

I'm working on a site and have Columns containing two smaller columns - the one on the left contains a featured image, and the one on the right contains a short description.

Template is for a single item post.

I had it set up so that the image in the left column, remaining in its original aspect, would fill its column horizontally or vertically scale (maintaining aspect ratio) to no more than 75% VH.

This ends up in a Query loop. It's basically a bunch of artwork with descriptions. However, after the update, I'm getting some layout issues that look like the bottom image, with a big gap between the artwork and the text. So, I'm trying to figure out what's causing the gap.

I do have some CSS set up, but I haven't changed this & it's been working for months.

Let me know what other additional info I can add here that might help. Hoping this is a fairly known or easy thing to fix.

Not sure how to troubleshoot this - any suggestions appreciated!

Thank you!

https://preview.redd.it/2blhmhop4tkh1.png?width=1052&format=png&auto=webp&s=95b201b9e43efd792c419de2c81abc022c336c8a

submitted by /u/oandroido
[link] [comments]
  •  
❌