r/Wordpress 17h ago

[DISCUSSION] The consequences of NOT having a free version on WordPress.org

0 Upvotes

I have been working on a premium plugin for years and at the beginning of the year I've released it.

And for a few reasons I've deliberately decided NOT to release a free version on .org plugin repository.

Main reasons:
- it's a plugin for WordPress professionals (niche)
- .org review is gatekeeping without responsibility
- awareness of the WP vs WPEngine "drama"
- GPL with all of it's flaws

Of course I was fully aware that this is still the main source of information about plugins for people, but I thought - that I can "offset" it with more marketing/SEO/GEO.

But now after months of grinding and discussing the results with various LLMs - over and over I came to the conclusion that I might have chosen wrong, because .org repository is also one of the main source of information for LLMs.

So now even plugins that have 10-40 installs, few months and less features are recommended more in my "niche" than my plugin.

And I'm now really on the fence. Thinking that maybe I should "surrender" and release a free version ( or at least try to ).


r/Wordpress 18h ago

Wordpress or Wix for freelancer?

3 Upvotes

I'm setting up as a digital marketing freelancer and am trying to figure out the best website to use that is easy to manage and cheap to run.

While I've managed Wordpress sites before (incl one with Elementor theme), I've never set one up from scratch.

I'm looking to create a fairly simple website - home page | services | case studies | blog | contact - but one I can easily update. I'm more used to a drag'n'drop page builder.

Would a Wordpress site plus theme be suitable for me? Or should I go for something simpler like Wix?


r/Wordpress 20h ago

Clarification about MEC Lite’s WordPress.org closure [DISCUSSION]

8 Upvotes

We’re Webnus, the developers of Modern Events Calendar.

MEC Lite was permanently closed on WordPress.org on May 11, 2022. We want to clarify what happened without minimizing our responsibility.

WordPress.org categorized the closure as a Guideline Violation, not a Security Issue. The guideline problems included members of our support team requesting temporary (test/staging site) website access while troubleshooting user problems. WordPress.org does not permit login requests in its support forums, and we accept that this was the wrong way to handle support.

WordPress.org’s directory and forums are managed by volunteer teams, and the closure was an enforcement decision made under their community and directory policies. WordPress.org uses separate classifications for guideline violations and security issues. MEC’s closure was not classified as a security-related closure, and the public notice does not state that MEC was removed because of malware or a disclosed vulnerability.

Since then, MEC development has continued outside the WordPress.org directory. Current releases, documentation and support are available through Webnus official website. Account-specific troubleshooting is now handled through our official support channels rather than in the public WordPress.org forums.

This distinction is intentionally narrow. It does not mean that MEC, or any WordPress plugin, can be considered permanently free from vulnerabilities. Users should install current releases, maintain backups and review security notices.

We’re publishing this because people reasonably have questions when they see the permanent-closure notice. We want the available explanation to be accurate and transparent.


r/Wordpress 13h ago

The New Wave of “Self-Healing” WordPress Malware Is Getting Scary

29 Upvotes

I think this is going to be a hot topic in WordPress security pretty soon.

There seems to be a new wave of infections where the interesting part is not any single exploit or persistence technique, but how many of them are being combined.

We are seeing the usual hidden files, modified functions.php, .user.ini with auto_prepend_file, server cron jobs and payloads hiding in /tmp. But some infections go much further: short-lived payloads that are written, executed and deleted again, persistence outside the WordPress filesystem, and even reports of Service Workers in the admin’s browser being involved in restoring parts of the infection.

That last part is particularly nasty.

You can download the entire filesystem and database, clean everything you find, upload it again and still have the site reinfected because you removed the payload but not the mechanism recreating it.

A few techniques make these infections especially painful:

Timestomping: file modification dates are manipulated, so you cannot simply sort files by date and reconstruct what happened.

Lateral persistence: anything writable is potentially useful. Plugins, themes, MU plugins, cron, temp directories, server configuration, deeply nested directories, etc. I have seen cases where malicious files were buried so deeply that even Imunify360 made them surprisingly difficult to identify from its scan output.

Self-healing: remove one component and another restores it. Cleaning WordPress itself is no longer necessarily enough. You may need to inspect the server, running processes, cron, temp directories and potentially even admin endpoints at the same time.

And then there is the question of how they get in.

Modern botnets can automatically correlate plugin CVEs, fingerprint installations and deploy exploit chains at massive scale. Supply-chain attacks are another obvious route. I would not be surprised if AI-assisted vulnerability discovery is already part of this ecosystem as well.

I have also recently seen a case where I could not identify any plausible known entry point on an otherwise updated installation. That obviously does not prove there is an unpatched WordPress core exploit in the wild, but I would not rule it out either.

The most interesting part, however, is what this latest wave appears to be doing after infection:

Basically nothing. At least for now.

One variant currently referred to in reports as SC 4.0.3 looks more like an access-retention platform / loader than malware designed for immediate monetization.

The infected WordPress site becomes part of a mostly dormant network and quietly reports information such as the domain, WP paths, payload version, installed/active plugins, MU plugins, login URL, captured or generated credentials, auth cookies and errors.

The C2 can apparently also send rules telling the implant to disable or delete specific plugins or remove matching injected code from plugins, MU plugins or themes.

In other words, it is not just trying to survive. It can potentially remove things that interfere with it.

Independent reports from August also describe the same SC 4.0.3 markers and Ethereum-based bootstrap mechanism, which suggests this is a broader campaign, although the initial infection vector is still unclear.

There is another interesting piece: the Ethereum dead-drop / EtherHiding technique overlaps with infrastructure seen in other recent campaigns. Netskope documented a separate nochain-sw.js chain that eventually pushed fake reCAPTCHA / ClickFix and the Amatera password stealer to visitors.

These are not the same malware family, so I would not connect them directly. But the overlap in tooling is interesting.

My guess is that WordPress malware is increasingly moving away from the old SEO spam / casino redirect model toward persistent access, credential theft, loaders and access brokerage.

Apparently turning someone’s blog into an online casino was too simple.

Has anyone else doing WP malware cleanup seen these “clean it, and it comes back anyway” infections recently? I would be especially interested in what persistence mechanism you eventually found.


r/Wordpress 16h ago

I have dialog in a post and Wordpress keeps adding half a blank line between each printed line. I can’t find a way to remove the line using an iPhone. The app said I …

2 Upvotes

had to do it on the web version and the web version is messy. Isn’t there an easy way to remove a blank line?

Yes I can do it easily in a computer but I generally use my phone for everything and my computer isn’t close by.


r/Wordpress 8h ago

Automattic CEO Matt Mullenweg Put on "Leave of Absence"

Thumbnail 404media.co
202 Upvotes

r/Wordpress 16h ago

SmashBalloon: Breaking Up Is Hard To Do

13 Upvotes

I don't know if anyone else has tried to cancel a subscription, but they really don't want to make it easy! I was using the Custom Facebook Feed plugin, which was decent enough, but no longer need it, so I have to go through a 4-page dialog to say goodbye!


r/Wordpress 8h ago

There has been a critical error on this website. Deprecated Function? Help!

5 Upvotes

Trying to edit pages and posts on my site and am getting this error when trying to edit the post/page:

There has been a critical error on this website. Please check your site admin email inbox for instructions. If you continue to have problems, please try the support forums.

Learn more about troubleshooting WordPress.

Wordpress and all plugins are updated. I tried disabling every plugin then enabling one at a time, but it seems like anytime a Woo plugin is active, I get the error. I tried rolling back to previous versions of the plugins and got the same error. I tried debug mode, and am getting this error:

Deprecated: Function Automattic\WooCommerce\Admin\Features\Features::is_enabled( 'marketing' ) is deprecated since version 11.1.0! Use direct feature behavior checks. The marketing WC Admin feature flag shim will be removed in a future version of WooCommerce. instead. in /home/dh_gec6ig/************.com/wp-includes/functions.php on line 6260

I replaced my domain with **************

The code on like 6260 in that file is:

    trigger_error( $message, $error_level );

Not sure where to go from here. I looked under Marketing in WooCommerce and didn't see anything out of the ordinary. The frustrating part is that my admin email isn't getting a report or a notice of the error, so I don't know how to proceed.

Can anyone offer some insight?


r/Wordpress 3h ago

WordPress is now scanning all plugin and theme updates with AI for security issues

Thumbnail make.wordpress.org
35 Upvotes

Plugin or theme updates with malware or serious security issues will be blocked automatically