• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
TheWayoftheWeb

TheWayoftheWeb

Content and Digital Marketing Specialists

  • Blog
  • The Cipher
  • About Us
    • Useful Resources For Businesses In Peterborough, UK
  • Contact Us
  • Show Search
Hide Search

Design & Development

WordPress 3.7 released, including Automatic Updates

October 25, 2013 By Dan Thornton

WordPress 3.7 is now available to install for all users. It’s codenamed ‘Basie’ for Count Basie and includes a number of new features, with the most notable one being automatic updates for maintenance and security updates. The full details are available in the Codex on the WordPress.org site.

There are some additional great new features, including:

  • Better password recommendations, as it will now detect common mistakes which can weaken passwords, such as dates, names, keyboard patterns etc.
  • Better global support for localised version of WordPress and language files for translations.
  • Improvements to Search.

WordPressLogo

Automatic updates: Some benefits, some risks:

Currently the Automatic Update function is purely for maintenance and security updates issued by WordPress, which will mean that most sites are now able to automatically apply these in the background, with additional security checks and safeguards now in place. It’s disabled if you need to use FTP for updates and requires your credentials, or if you’re using SVN or GIT.

So basically the majority of self-hosted WordPress sites will be able to run automatic updates.

Benefits:

The benefit is that a lot of WordPress sites can go weeks, months or years before the administrator will update them to the latest version of WordPress, which is a big security problem. Generally security and maintenance releases are tackling exploits which can or have been used maliciously, so by not updating regularly, you’re leaving a big invitation to anyone attacking WordPress installs, particularly when they are probing sites en masse.

If you’re using a non-English install, Language Packs should also be automatically updated.

Currently, automatic updates won’t be enabled for major releases, themes or plugins, so those updates will still need to be enabled manually. If you wish, you can enable automatic theme and plugin updates with some code changes.

Risks:

There are some issues which cause us some concern regarding automatic updates.

  • There is no way to turn these on, or off, without editing code in your wp-config.php file, which not everyone is comfortable doing (Although we’d urge anyone to backup everything properly, or to create a test site, and then have a go).
  • Security and Maintenance patches may cause conflicts with existing themes and plugins. In addition, other fixes may sometimes be included in these releases.
  • Lack of scheduling for updates – given the potential for disruption with any update, we make sure we implement them at times which are less critical for our clients, particularly with regards to eCommerce etc. With automatic updates running in the background, you won’t know when your site will be updated, and have no way to direct it to be at a convenient time. For instance Basie appeared late on Thursday night UK time, so potentially we wouldn’t discover any conflicts until starting work Friday morning.

Our recommendation:

For non-business critical WordPress sites, we’d suggest that you upgrade to WordPress 3.7 and enjoy the automatic updates. Certainly I’ve updated my personal site straight away to test and explore Basie and check how it all works.

The potential risks for most sites from automatic updates are probably much less than the risk of being exploited for running a massively out of date WordPress install.

For anything relating to business, including all our client sites, we’ll be disabling automatic updating for the following reasons.

  • We already monitor and quickly update WordPress versions, themes and plugins upon releases and testing to confirm they won’t break any existing sites or functionality.
  • We need to ensure that any new versions do not impact on increasingly complex functionality, such as eCommerce platforms.
  • And we need to make sure that when we’re updating business critical sites, we’re doing it at a time when there is minimal disruption in the event of any problems. Generally updates go fine, take a few seconds, and the site is back. And if there are any problems, we can always roll back straight away to the backup, but we’d rather keep any disruption away from peak business hours.

If you do want to disable automatic updates, then the details are included in this comprehensive guide to Automatic Core Updates by Dion Hulse. The simplest way to disable it is to add define( 'AUTOMATIC_UPDATER_DISABLED', true ); to your wp-config.php file

WordPress 3.6 is now available

August 2, 2013 By Dan Thornton

The latest version of WordPress, which is version 3.6, is now live with some new functions and features. As always, we’d recommend backing up your site before starting any upgrade procedure, which is a process we undertake for many of our clients.

The release is codenamed ‘Oscar’:

Features for WordPress users:

For general users and authors, the main features of the new release are:

  • New Twenty Thirteen default theme.
  • Revamped Revisions to save every change with a new interface
  • Post Locking and Augmented Autosave to allow saves by authors and taking over post editing when more than one author is working on an individual post.
  • Built-in HTML5 media player for native audio and video embeds.
  • Improved integrations and oEmbed support for Spotify, Rdio and SoundCloud.
  • Easier Menu Editor.

Developers also benefit from a new audio/video API with access to metadata like ID3 tags, HTML5 markup for more elements, better filters for revisions, and a long list of additional changes.

WordPressUpdate

We’ve already updated this site to 3.6 and some other test sites, and haven’t experienced any substantial problems. But it will depend on the plugins and frameworks you are currently using, so please do make sure you back up before updating, especially if you don’t have regular backups already taking place.

Make sure you upgrade to WordPress 3.5.2

June 24, 2013 By Dan Thornton

WordPress version 3.5.2 was released just before the weekend. We’ve already advised all clients to upgrade, along with making sure all of our own sites are running the latest version, as 3.5.2 is an important security release.

The new WordPress version fixes 7 security issues, and also contains some additional hardening measures, which is important given the recent spate of brute force attacks on a huge number of WordPress sites. The majority of attacks focus on basic defaults and outdated software, which is why it’s so important to stay current.

locks

Security Fixes in 3.5.2:

From WordPress.org:

  • Blocking server-side request forgery attacks, which could potentially enable an attacker to gain access to a site.
  • Disallow contributors from improperly publishing posts, reported by Konstantin Kovshenin, or reassigning the post’s authorship, reported by Luke Bryan.
  • An update to the SWFUpload external library to fix cross-site scripting vulnerabilities. Reported by mala and Szymon Gruszecki. (Developers: More on SWFUpload here.)
  • Prevention of a denial of service attack, affecting sites using password-protected posts.
  • An update to an external TinyMCE library to fix a cross-site scripting vulnerability. Reported by Wan Ikram.
  • Multiple fixes for cross-site scripting. Reported by Andrea Santese and Rodrigo.
  • Avoid disclosing a full file path when a upload fails. Reported by Jakub Galczyk.

As always, you should back up your site before any upgrade, and your update is likely to include changes to the database. If you’re struggling with WordPress, give us a shout and see if we can help!

New Facebook Open Graph tags for writers and publishers

June 21, 2013 By Dan Thornton

You may be familiar with the Author and Publisher tools which Google+ offer to websites, and now Facebook has added some additional tools for publishers, journalists and writers to boost their content on the social network.

The new Open Graph tags were officially revealed yesterday, and are as follows:

  • article:publisher lets a publisher link an article to their own Facebook page. When the article is shared in News Feed, a “like” button is displayed so people can like the publisher page.
  • article:author lets a publisher link an article to the Facebook profile of the author. When the article is shared in News Feed, a “follow” button is displayed so people can follow the author. The author needs to have Follow activated on his or her profile for this button to appear.

They are coded as follows:

<meta property="article:publisher" content="https://www.facebook.com/thewayoftheweb" />

<meta property="article:author" content="https://www.facebook.com/danthornton" />

This means ‘Follow’ and ‘Like’ buttons will appear for those who haven’t already followed the author or liked the Publisher page, when that content crops up in their newsfeed.

So well worth implementing to make the most of your visitors sharing your articles and content on social networks.

The BBC, Facebook and ‘The Supermarket Effect’

September 23, 2011 By Dan Thornton

With the BBC unveiling a new homepage and Facebook rolling out a whole raft of new features, the predictable ensuing uproar at change is taking place.

Back in 2008, I wrote about what I termed ‘The Supermarket Effect‘ when launching a new design or features on an existing site. As Hugh McLeod once memorably illustraed – ‘Technology Changes, Humans Don’t‘. And I’m not sure the business/media owner approach to unleashing their latest effort to guess what we all want has changed much in the last 3 years, either…

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Go to Next Page »

Primary Sidebar

Join us…

  • Facebook
  • Instagram
  • LinkedIn
  • RSS
  • Twitter

We only exist to deliver results for your business. So you get fresh Content, expert SEO, engaging Social Media, or a new Website which is right for you – and your customers.

We help you build your brand, reach more customers and increase your revenue

Search

Categories

Creative Commons License
This work by TheWayoftheWeb is provided under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

Start growing your business today Contact Us

TheWayoftheWeb

Copyright © 2026· TheWayoftheWeb Ltd. Company Number 08038527. ICO registration: ZB397650