WordPress 4.8.2 Security and Maintenance Update released

WordPress 4.8.2 Security and Maintenance Update released

On September 19, WordPress released a new Security and Maintenance Update.

Needless to say: if you are a WordPress website owner, you should update now, if you didn’t already. Also, be sure to backup your website, if you didn’t do it recently!

To Backup your website is always important before installing Core updates. This prevents issues (such as your website becoming broken or unbrowsable) from rising, especially with Plugins, as they may not always be 100% compatible with the new version.

Need help with your WordPress Backup and Update? Contact us!

What does WordPress 4.8.2 update fix?

Cross-site scripting vulnerabilities (XSS), mostly.
This is a short list of the main bugs that have been found and that the 4.8.2 update fixes, along with a brief explanation, where needed:

  • Cross-site scripting (XSS) vulnerabilities were discovered:
    • in the oEmbed discovery;
    • in the visual editor;
    • in the plugin editor;
    • in template names;
    • in the link modal.

XSS is a kind of vulnerability used to bypass websites’ access controls.

  • Path traversal vulnerabilities were discovered:
    • in the file unzipping code;
    • in the customizer.

A path traversal attack (aka directory traversal attack) aims to access files and directories that are stored outside the web root folder.

  • An open redirect was discovered on the user and term edit screens.

Through open redirects an attacker may successfully launch a phishing scam and steal user credentials. This can happen by redirecting the victim to links identical to the original site, so to have a more trustworthy appearance.

There are other 7 maintenance fixes. If you are interested, you can check the full Release Notes for WordPress 4.8.2 directly from their website.

We are available to chat with you over these and other WordPress related issues anytime. Contact us!

Let us help you find what you need! Fill our secure form!

1 + 6 =

WP-Base-SEO: fake SEO Plugin for WordPress it’s actually a Malware

WP-Base-SEO: fake SEO Plugin for WordPress it’s actually a Malware

If you are Administrator of a WordPress website, pay attention!

The security firm SiteLock has reported that WP-Base-SEO, a fake version of the legit WordPress SEO Tools plugin, has infected lots of WordPress websites.

As SiteLock shows, WP-Base-SEO does a very good job in faking legitimacy, providing references to the official WordPress Plugin Database and instructions on how to use the plugin properly.

Still, digging deeper in the main PHP files of the plugin, they found out a base64 eval request. It’s a PHP function very often used for malicious purposes and, as such, its use is disregarded by PHP.net. In this case, it opens up backdoor access to the website.

The security news website Threatpost states that over 4.000 WordPress sites have been infected by WP-Base-SEO. It is likely that the attackers have mass-scanned WordPress websites searching for outdated plugins to target. This is a very common practice.

Just to provide an example, in April, 2016 an outdated version of WordPress RevSlider image slider plugin, was held responsible for 2.5 terabytes data leak that went under the name of “Panama Papers”.

How to increase your WordPress website Security?

As always:

  • Keep the WordPress Core updated to the latest version
  • Pay attention when installing a new WordPress plugin on your website: look for good ratings and legit feedback from the WordPress Plugin Database users
  • Keep your plugins updated to the latest version
  • If a plugin has not provided any update in the last few months, consider removing it from your website.

We at Handyweb have dealt with WordPress Security issues and can help you if you need solutions! Contact us!

Let us help you find what you need! Fill our secure form!

10 + 12 =

WooCommerce 3.0 Major Update Released

WooCommerce 3.0 Major Update Released

WooCommerce 3.0 is a new Major Update for the worldwide-known eCommerce plugin for WordPress.

Codenamed “Bionic Butterfly”, this new version of the plugin has been in development since August 2016 and in beta since December 2016.

Let’s find out what’s new!

A new Product Gallery

This is probably the most visible improvement to both the end user and the administrator. The WooCommerce 3.0 Update comes with a new product gallery, providing a really clean, slick and intuitive user experience.

Mobile browsing of such product pages has been really improved: tap on a thumbnail to display the image in its true size, swipe to scroll, pinch to zoom, swipe up to close.

As you can see in the above video, the whole page is fully responsive without compromising design quality.

CRUD classes and new CLI for developers

WooCommerce 3.0 also introduces CRUD (Create, Read, Update, Delete) classes, to help developers retrieve data from the database more easily, and a new Command Line Interface powered by the REST API.

If you are a developer, you can read all about the new CRUD classes and the new Command Line Interface over to WooCommerce Official Development Blog.

Other Improvements

Other than plenty of performance improvements, WooCommerce 3.0 comes with some tweaks that benefit both the Administrator and the User.

This is just a quick round-up of all the features and improvements included in the “Bionic Butterfly” Update. For more details you should check the official Blog post about it!

Backup before updating

You should always backup your website before an update, especially if it’s a Major Update such as this one.

We are experienced in WooCommerce setup and management, as many of our clients make use of the plugin for their eCommerce businesses. We can help you and guide you through the process of backing up and updating your WooCommerce installation.

Let us help you find what you need! Fill our secure form!

8 + 11 =

WordPress 4.7.3 Security and Maintenance Update released

WordPress 4.7.3 Security and Maintenance Update released

WordPress has just released a Security and Maintenance Update.

The 4.7.3 update fixes important secuirity issues that 4.7.2 and previous updates still didn’t manage to fix completely.

Of course they suggest to install the update immediately and. as WordPress users ourselves, we can’t help but strongly suggest you to do that.

So, if your website uses WordPress as a Content Management System (CMS), you should backup your website and update WordPress Core to the latest version.

To backup your website is always important, especially before installing Core updates, so to prevent issues. Also, if your website has Plugins installed, these may not always be 100% compatible with the new version which can lead to your website becoming broken or unbrowsable.

Need help with your WordPress Backup and Update? Contact us!

What does WordPress 4.7.3 update fix?

Being an open source, heavily community-reliant CMS, WordPress updates are usually based on the huge amount of feedback coming from its huge user base (WordPress 4.7 has been downloaded over 17 million times).

This is a short list of the main bugs that the 4.7.3 update fixes, along with a brief explanation, where needed:

  • Cross-site scripting (XSS) via media file metadata.
    XSS is a kind of vulnerability used to bypass websites’ access controls.
  • Control characters can trick redirect URL validation.
  • Unintended files can be deleted by administrators using the plugin deletion functionality.
  • Cross-site scripting (XSS) via video URL in YouTube embeds.
  • Cross-site scripting (XSS) via taxonomy term names.
  • Cross-site request forgery (CSRF) in Press This leading to excessive use of server resources.
    CSRF is a type of malicious website exploit where unauthorized commands are transmitted from a user that the website trusts.

There are other 39 maintenance fixes. If you are interested, you can check the full Release Notes for WordPress 4.7.3 directly from their website.

We are available to chat with you over these and other WordPress-related issues anytime. Contact us!

Let us help you find what you need! Fill our secure form!

4 + 8 =

Brought to you by Handyweb.ie 

Phone: +353 (0) 44 93 45145
Email: info@handyweb.ie
Services: Web and App Consultants, e-Commerce, Responsive Web Design, Search Engine Optimisation, Digital Marketing, Social Media, App Development, Online Payments, Online Business Automation

AMP becoming a new trend in SEO in 2017?

AMP becoming a new trend in SEO in 2017?

Apparently, no more than a week ago, when browsing Google News from a mobile device, just about 30% of the results were AMP. But, on January 29, AMP results increased up to 70%.

Is this event marking the beginning of a new trend for SEO? It’s probably too early to tell, but it’s better to be ready.

What is AMP (Accelerated Mobile Pages)?

First announced by Google in October 2015, AMP basically translates to web pages stripped down of most of the “eye-candy” that makes them heavy, slow to load.

In an increasingly mobile-oriented world, page loading speed is more important every day.

So, the AMP Project‘s main purpose is to make mobile content available as fast as possible. It has been shown that about 40% of Mobile users leave a web page if its loading time is more than 3 seconds.

You can see that this is bad both for the user, who won’t see your content, and for you, because you will have lost a potential meaningful visit.

Test AMP search results with the demo provided by Google itself. Visit g.co/ampdemo from your mobile device.

If you talk to publishers about this, you will probably get them interested!

What is the difference between AMP and mobile-friendly pages?

If you are one of our customers, you already know how much we are focusing on building mobile-friendly websites. Then, you may be wondering: is AMP different?

A quick example, took from this article on the BBC News website (AMP version here).

Responsive vs AMP example

The one on the left, is an example of non-AMP responsive design. You can see the header, the menu, the search box and other elements appearing.

On the right, instead, there is the AMP version of the same page, stripped down to mostly the actual images and content.

Even if AMP are indeed mobile-friendly pages, their difference lies in the amount of code used in the page itself.

A non-AMP mobile friendly page will most likely have code that makes animations, scrolling effects and popups appear on the screen. AMP pages get rid of that, without compromising the actual content: images, videos and text are left untouched.

Quoting Google itself: “We want webpages with rich content like video, animations and graphics to work alongside smart ads, and to load instantaneously”. So, it is worth noting that AMP does not necessarily mean no Ads.

AMP and non-AMP version of the same page can currently co-exist without causing Duplicate Content issues. Make sure that the AMP versions your pages have a rel=canonical tag that links to the non-AMP ones.

Is AMP going to be used as a Ranking Signal?

Again, it’s probably early to tell. It’s worth mentioning that back in February 2016, in a Google Webmaster Central Hangout, John Mueller said that AMP was not yet a Ranking Signal.

Still, considering the sudden growth of AMP results in Google News, and the fact that Google has been placing mobile experience first for a long time now, then it’s easy to imagine that it could happen. We’ll stay on the watch for any change.

Also, Search Engine Journal collected insights from SEO professionals around the world, some of which are keeping their eyes on what kind of importance Google may give to AMP in 2017.

What it is sure is that AMP is great for SEO in general. If you build AMP pages, you will basically build:

Mobile-friendliness, Page Speed and User Experience are indeed Ranking Signals!

Also, with AMP in mind, you may end up writing better content, since you would have to pay far less attention about the layout.

How to setup AMP pages (on WordPress)

If your website is built using WordPress as a CMS, then to setup a basic AMP on your website we suggest you to install two plugins: AMP by Automattic and AMP for WP by Ahmed and Mohammed Kaludi.

Once you installed them, you can access to them under the same panel, located in Dashboard > AMP

AMP WordPress Plugin Dashboard

From this page, you can help yourself through the provided links to learn how to setup AMP properly.

Be sure to always have the latest WordPress version installed and also always perform a backup of your website before installing plugins.

How to setup AMP pages (on non-WordPress websites)

If you are not using WordPress, the best place to get started is the Guide provided by the AMP Project itself.

Need help to setup AMP for your website?

If you don’t have time to setup AMP on your own, or just need some help, contact us: Handyweb can help!

Let us help you find what you need! Fill our secure form!

9 + 5 =

Brought to you by Handyweb.ie 

Phone: +353 (0) 44 93 45145
Email: info@handyweb.ie
Services: Web and App Consultants, e-Commerce, Responsive Web Design, Search Engine Optimisation, Digital Marketing, Social Media, App Development, Online Payments, Online Business Automation

Google Mobile Interstitial Penalty gets sites showing “annoying” popups

Google Mobile Interstitial Penalty gets sites showing “annoying” popups

On January 10, Google has updated its algorithm, applying the so-called Mobile Interstitial Penalty.

If your website pages features elements that make the content not easily accessible to your mobile visitors, your ranking on Search Results Page may suffer a backlash.

This should mostly target pages that appear on mobile search results.

Desktops popups and interstitials are still not penalised as much. I wouldn’t be surprised if this should change in the future, though.

How to avoid Google Mobile Interstitial Penalty?

If your website, when visited from a mobile device, features Popups, Modals or other Interstitials that:

  • Cover your content (even just by graying it out)
  • Cannot be removed unless you click the “X” to close them
  • Cannot be remuved unless a specific amount of time has passed (pretty much like some ads on mobile apps).

You should remove them right away.

Only exceptions, according to Google, are popups that serve a purpose such as displaying informations about Cookie Policy or Age Verification popups.

Like most of what is related to search engine’s ranking factors (and Search Engine Optimisation in general), think first and foremost in terms of user experience.

Ask yourself: will this feature slow my visitor’s ability to browse my content? If it does, you should remove it.

Luckily it is Google itself, in the blog post that announces the algorithm update, that shows us some examples of which are to be considered Good and which Bad Interstitials.

Bad Interstitials vs Good Interstitials

Examples of intrusive interstitials

Examples of intrusive interstitials – Source: Google

These are examples of intrusive popups and interstitials, according to Google.

The first should be a Modal. The second and third ones are standalone interstitials.

As you can see, all of them cover most – if not all – of the content of a page. Also, they are advertising a paid service.

A visitor reaching the page from a mobile search results – will likely be far more interested in the actual content, rather than in stuff that gets in the way.

Just in case you may need it, here is an article about the difference between a Popup, an Interstitial and a Modal.

 

Examples of good interstitials

Examples of good interstitials – Source: Google

These are examples of interstitials that are less likely to get you penalised by Google.

The first one is an example of what a Cookie Policy popup may look like. The second one is an actual interstitial, covering the whole content, but for the purpose of Age Verification.

The last one is an advertisement, but it is included in a small, simple banner. It doesn’t really block the actual content of the website from being browsed.

So, yes! It is possible to have ads on a website’s mobile version without being penalised by the Mobile Interstitial Penalty. Just be reasonable!

If you want to read more about the topic, I suggest you to read this article published on Search Engine Journal.

Do you need help to avoid being penalised by Google’s Mobile Interstitial Penalty? Contact us!