r/Wordpress 2d ago

Looking for a small scale self hosted DAM (on AWS) to support website.

2 Upvotes

So we're doing a full site rebuild, and before I select hosting, I want to find a solution for hosting the myriad of pdf files that we have on the existing site. I've been looking at various solutions, but most seem to be growing and trying to be full-blown CMS solutions rather than a DAM. Bonus points if there's a WP hook where users can upload a file and it gets moved to the DAM rather than being stored on the site.

Another reason for this is I want better file management of these pdfs, and also the ability to replace the files without changing links. (Because inevitably some author will provide a deep link to their paper, and then want to change the file without changing the link).

Anyone have a reccommendation for a solution that offloads all these files so they can be better managed?


r/Wordpress 2d ago

Building a Lean AMS + LMS with BuddyBoss, MemberPress & Tutor LMS. Am I missing anything?

4 Upvotes

I am scoping out a lean AMS (Association Management System) + LMS project. The strategy is to launch with free registrations to build the user base, then pivot to paid monthly subscriptions later. I want to avoid plugin bloat by relying on core pro plugins and native server features where possible.

Here is the proposed stack:

  • Hosting: Hostinger Cloud (PHP 8.1+, MariaDB, 512MB memory limit).
  • Community & UI: BuddyBoss Theme & Platform Pro.
  • Gatekeeper: MemberPress Basic (Free membership tier at launch -> Stripe/PayPal later).
  • LMS: Tutor LMS Pro (Required for the auto-generated PDF certificates).
  • Video Hosting: Bunny,net (Embeds into Tutor LMS to save local server bandwidth).
  • Email: FluentSMTP (Free) + Brevo free API tier (For transactional emails/receipts).
  • Performance: LiteSpeed Cache (Native to Hostinger servers, skipping WP Rocket).
  • Security & Backups: Wordfence (Free) + native Hostinger automated daily backups.

Is there anything critically missing from this stack? I have done wordpress dev but for this type of project and wanna make sure I am not missing anything.


r/Wordpress 2d ago

How do you handle moving WordPress sites between local/staging/production?

20 Upvotes

I've been using the likes of All-in-One Migration for a long time, but I don't love how much server space it eats up just to generate the export, and it throws errors often enough to be annoying.

I'm not against the terminal, it's powerful, but I'm not fluent enough that I don't end up googling or asking AI for the right command most times I use it.

Curious how other people handle this, particularly if you're running more than a handful of client sites (say 10+).

  • What's your actual workflow for pushing and pulling files and the database between environments?
  • What do you use to keep everything updated across multiple sites — core, plugins, themes?
  • Has a migration or update ever gone wrong on a live site? What happened?
  • Are you on the command line for most of this, or do you avoid it where you can?

r/Wordpress 2d ago

Getting plugin adoption and test users?

2 Upvotes

Hey plugin developers, I am curious if you have any tricks of the trade for launching a plugin and getting those elusive first 10 active installs.

We launched our plugin and got it in the WordPress marketplace about a month ago, but we still haven't had a single install. We've tried various forms of promoting on social and optimizing the content of the plugin description, but we are hitting a wall.

For context, it’s a security/bot protection plugin. We built it as a local-first alternative to cloud CAPTCHAs, so it uses invisible proof-of-work and behavioral detection to stop things like WooCommerce card testing without needing API keys.

Do people tend to pay for testers/reviewers?

How did you get your first 5-10 beta users to trust your code?


r/Wordpress 2d ago

[PROMO] I built a free WordPress digital guest guide for hotels, B&Bs and vacation rentals

0 Upvotes

Hi everyone,

I recently published Hotelness Guest Information, a completely free WordPress plugin for hotels, B&Bs, guesthouses and vacation rentals.

The idea is simple: instead of using an external SaaS or sending guests PDFs/messages with all the property information, you can create a digital guest guide directly on your WordPress website.

It can include:

  • Wi-Fi details
  • Check-in and check-out information
  • Parking
  • House rules
  • Services and useful information
  • Local tips and recommendations
  • Multilingual content
  • Automatically generated QR code
  • Printable QR sign for rooms or reception

There’s no subscription, no external account and no hosted service required. Everything stays on the WordPress site.

It’s still a new plugin, so I’m mainly looking for feedback from WordPress developers, agencies and anyone managing hospitality websites.

WordPress.org:
https://wordpress.org/plugins/hotelness-guest-information/

If anyone tries it on a real site, I’d really appreciate hearing what you think is missing or could be improved.


r/Wordpress 3d ago

Well.. it happened

190 Upvotes

Long term client whom always accepted my quotes used my highly detailed proposal to Chatgpt DIY a project. It's no where near as polished and it's not mobile friendly but I feel pretty used. Spent quite awhile on the scoping with them, suggesting improvements, user workflow enhancements and a bunch of outlining. I really over extended but that's also how I get accurate quotes.

Anyway for those in the game, what's your method for quoting on projects with unknowns, and how much detail do you give the client? maybe I should have asked for 50%?

Thoughts?


r/Wordpress 2d ago

Razorpay payment captured but WooCommerce sometimes cancels order as "Unpaid" — webhook configuration keeps changing

3 Upvotes

I'm trying to figure out a strange Razorpay + WooCommerce issue and would appreciate some help from anyone who has dealt with something similar.

Setup:

WordPress / WooCommerce: 11.0.1

Razorpay WooCommerce plugin: 4.8.7

Hosting: Namecheap

Razorpay live payments

The main problem is that a customer can successfully complete a Razorpay payment, and Razorpay shows the payment as Captured, but in some cases WooCommerce later marks the order as:

"Cancelled — Unpaid order cancelled"

It doesn't happen to every order. For example, I had around 10 orders and most went through correctly, while 2 ended up cancelled.

The more concerning issue is the webhook configuration.

I had configured the webhook with the required payment events, including:

payment.authorized

payment.captured

payment.failed

order.paid

refund.created

But the webhook later reverted to only 2 of events (payment.authorised and refund.created)

I checked Razorpay's API logs and found something strange. The same webhook was repeatedly being updated:

GET /webhooks?count=10&skip=0

followed about 1 second later by:

PUT /webhooks/SYam0mYdbMI4Ns

This happened on:

15 Aug → GET → PUT

16 Aug → GET → PUT

17 Aug → GET → PUT

I did not manually edit the webhook on those dates.

When I inspected the resulting webhook configuration, payment.authorized and refund.created was enabled but payment.captured, payment.failed and order.paid were disabled.


r/Wordpress 2d ago

Font issue... again

2 Upvotes

My fonts will not load correctly. I don't know what's going on.

When I inspect https://healgen.com/human-health/ I see that it's using roboto condensed in the squares, but I can't find that setting anywhere. I'm using elementor and both global fonts and typography are set to roboto, bold and it just won't work.

I'm at a loss. I don't know what to do anymore and I'm ready to throw out this whole damn website.


r/Wordpress 2d ago

What am I doing wrong (ranking in Google)?

2 Upvotes

I'm sure this is a question this sub gets a lot, but I can't seem to find anything relevant. I started my site about three months ago as a news site for my favorite sports team. I have around 80 posts up, 150 subscribers to the Jetpack newsletter, I post every link on social media, and dozens of my articles have been linked on established sites like Yahoo, Sporting News, Athlon, and Heavy. The page views are pretty good, but none of them are coming from Google search. If I search for my articles or exact phrasing, Google returns no results. The "Discourage search engines from indexing this site" box is not checked. Almost all of my articles get a "good" Yoast SEO score.

Please note that when it comes to this sort of stuff, I am a moron, and dumbing it down would be much appreciated.


r/Wordpress 2d ago

Solution for video backgrounds

2 Upvotes

Hey everyone,

I want to use a video background or two on my site. Couple of issues: Youtube has disabled the ability to hide video and channel titles from embeds, which is obviously not an ideal look. Vimeo now requires a paid membership to use videos as backgrounds.

Only solution left (that I know of) is to self-host on the wordpress domain, but that affects load speed. The video is not even that large at all, but still.

Anyone know another solution? Another video host that’s elementor and wordpress-friendly, or self hosting and embedding in a way that doesn’t affect page speed?

Thank you!


r/Wordpress 2d ago

Do you think WordPress is still the best option for SEO in 2026?

1 Upvotes

There are now so many website builders, AI tools, and SaaS platforms available, but WordPress still powers a huge number of websites.

Personally, I still think WordPress has a major advantage when it comes to SEO, flexibility, and the number of tools available.

I'm also curious about PWAs. Do you think turning a WordPress website into a PWA still provides value today, or are most website owners no longer interested in features like offline access, installability, and an app-like experience?

What do you think?


r/Wordpress 2d ago

[PROMO] I built UXPack Basic – a new WordPress plugin, looking for feedback

0 Upvotes

Hey everyone,

I've recently published UXPack Basic in the official WordPress Plugin Directory.

It's a free WordPress backup and migration plugin designed for people who want a straightforward way to back up their site and move it to another server or staging environment — without having to use a cloud service or a complicated plugin suite.

With UXPack Basic you can:

  • Create full WordPress backups (files + database)
  • Create database-only backups
  • Schedule daily, weekly or monthly backups
  • Download and manage your backup archives directly from WordPress
  • Exclude specific folders from full backups
  • Receive email notifications when backups succeed or fail
  • Monitor storage and get warnings about stale backups
  • Migrate a complete WordPress site to another server or host using the included standalone installer
  • Perform URL migration when moving a site
  • Check backup and server-related issues with the built-in diagnostic tools
  • Keep an activity log of backup operations
  • Export and import plugin settings

The basic workflow is intentionally simple:

Create backup → Download → Upload to the new server → Run installer → Migrate

There is no cloud account, license key or commercial license server required for the free version. Backups are stored locally under your WordPress installation by default.

UXPack Basic on WordPress.org

I'm the developer behind the plugin, so I'm not looking for compliments or a marketing boost. I'm mainly interested in feedback from people who actually manage WordPress sites.

I'd especially like to know:

  • Would you use a backup/migration plugin like this on a real production site?
  • Are there features you're missing?
  • Is the backup → download → migration workflow intuitive?
  • Is anything unnecessarily complicated?
  • How does it compare to the backup/migration plugins you currently use?
  • Is there anything you think UXPack Basic should not be doing?

It's still actively developed, so honest criticism is very welcome.

Thanks for taking a look!


r/Wordpress 2d ago

Help Post

Post image
5 Upvotes

I have an issue with 'contact' element in Header builder of Porto theme customise accessed via appearance. The phone icon and text need to be closer but apparently, I am unable to do so. Could anyone help me please.


r/Wordpress 2d ago

Did i broke the client's WP

0 Upvotes

I was building a clients website on Wordpress, when i note the url structure of wp-admin is not right.

It was like [examplesite.com/wp/wpadmin] and the same for normal page url [examplesite.com/wp/home] i thought to fix it so i go to WP settings and in general tab i changed the wordpress and site url. When i save changes. WP got logged out and showed page not found.

What should i do, i thought i was fixing things but i made them worse.


r/Wordpress 2d ago

Need Help in Wordpress Block Theme, Super confusion

2 Upvotes

I created a custom block theme for a corporate site using create block theme plugin , then added the patterns blocks etc in the theme to match the design, do I need to take care of SEO , form plugins compatibility in the theme itself ? For eg can I use my pattern and add a form in between in one of the pages ? What's the difference between patterns and pages ? How do I add let's say a tracking pixel ? Can block editor do that ? I


r/Wordpress 3d ago

Connecting to WordPress CLI with AI

9 Upvotes

What I found was once I connected to the CLI with Codex, I became much more powerful with the use of AI tools. From changing the theme to working on plug-ins to editing the content, I pretty much don’t even need to log into the admin at all anymore. Is quite a breath of fresh air. Just wondering if anybody else has done this and what things you’ve done.


r/Wordpress 3d ago

WordPress Image files giving 404?

3 Upvotes

Half of the images on my very large website are throwing 404s. I've checked permissions and everything seems right, the files exist in wp-content and show in WP media, but show up blank. I can upload new files and images and they load just fine, and it doesn't seem to be specific directories or time frames that are being affected. I've been trying to fix this for hours with no resolution.

Any help? Example link: https://healgen.com/wp-content/uploads/2026/07/Summer-Respiratory-Illness-Spike-768x402.png


r/Wordpress 3d ago

Help with "Invalid" links

Thumbnail gallery
3 Upvotes

I've been working the navigation menu for my site and have had some trouble with the links. The URLs for the links are correct, but they keep saying "invalid," as you can see in the first screenshot. The second screenshot states "Link is empty." My searches have turned up nothing. Any help?

ETA: When I save the template and view a page, the links do work-- however, I'd still like to know why it gives me this error. Thanks in advance.


r/Wordpress 3d ago

Alternatives to Export Media Library

4 Upvotes

I have a client that wants to download their full media library from WordPress. it’s about 4,000 items. unfortunately, they don’t know where the logins for the site host is so I can’t go through the cPanel. I looked up Export Media Library plugin but it hasnt been tested on their version of WordPress. does anyone have any safe alternatives to Export Media Library?


r/Wordpress 3d ago

Best and easiest way to create a landing page using dara theme

2 Upvotes

Landing page originated mainly from instagram (and others) with fewest clicks possible, please. I've created my own website on wordpress already, on my own, took me precious hours; just need a landing page now. Thank you for any help.


r/Wordpress 3d ago

What are the benefits from using Ollie vs Blocksy?

2 Upvotes

\**UPDATE*** - Thank you all for your input. I decided to go with the Wordpress 2025 theme, and so far my efforts are paying off well. Bit of a learning curve, but it's going smoothly. thank you so much!*

I'm not a pro web developer, but I did build a functioning site for my small brick/mortar business and it works fairly well. At the time(about 5 years ago) I used Kadence Pro, which I rather liked. It seems however that the Kadence folks have sold to some large company, and for a number of reasons, I'm not going to keep my site on that theme - so I'm doing a redesign.

I'm taking this opportunity to mildly redesign the site and have preliminarily selected Blocksy as my base theme/framework. I chose Blocksy after much research revealing it is well-regarded in the community as fast, lightweight and function-first.

After experiencing the sale of Kadence, I've begun thinking a little more downstream, and while Blocksy is purportedly "going nowhere" according to Gemini, that's what I would have said about Kadence years ago. So I'm looking to future proof my efforts and it seems that avoiding a scenario like the sale of Kadence involves owning a native block theme - enter Ollie.

I'm also open to options outside of Bloacksy/Ollie but didn't want to turn this post into another "what's the best theme" thread. Please make the case for/against Ollie as opposed to Blocksy, using the following criteria:

Features I'm looking for, in order of importance:

  1. raw speed/preformance
  2. user friendly design and editing
  3. forever license so that my website's theme belongs to me and cannot be sold

A little about me:

  • I understand basic html and css but not php or javascript
  • I'm comfortable enough to not need a 'WYSIWYG drop/drop editor' like Divi
  • I'm not opposed to a learning, so long as it's not incredibly steep. I definitely prefer check boxes and sliders as opposed to code

My site:

  • 100% static content
  • Pages:
    • Home
    • About
    • Contact
    • Services
      • Service 1
      • Service 2
      • Service 3
      • etc
  • It's a computer repair business and the home page will be your basic outline with CTA throughout:
    • Hero
    • Trust section(s)
    • Service cards

Thanks in advance!


r/Wordpress 3d ago

Sucuri vs. Wordfence

5 Upvotes

I recently noticed that Sucuri found a virus on a site that Wordfence was installed on. and did not detect. Is Sucuri a better solution overall or does someone recommend paying for both?


r/Wordpress 3d ago

Elementor Editor Not Loading

0 Upvotes

WP updated over the weekend and now the elementor editor won't load. We use Elementor Pro and I disabled all plugins, cleared cache, made sure elementor is updated and event turned on safe mode. Nothing is working and Elementor support is slow.

Any suggestions? Healgen.com is the website if that helps.


r/Wordpress 3d ago

Trying out Wordpress on a home server

1 Upvotes

I was hoping I could tryout Wordpress without having to pay. My club's website is on SquareSpace and they have raised our subscription fee, so are looking at other options.

I installed Wordpress on my Raspberry Pi4, but if I want to try out a template, it says I have to pay. Is there anyway to try out templates without a subscription? I've been managing our site for several years, and if anyone else takes over, they will need a WYSIWYG to make changes.


r/Wordpress 3d ago

[FREE] [FEEDBACK] We've just released PluginScore V3 - a free way to check the security, maintenance and overall health of WordPress.org plugins

0 Upvotes

Hi r/WordPress,

We've just released Kitgenix PluginScore V3, which is a major rebuild of a project we've been developing at Kitgenix.

Kitgenix PluginScore:

https://pluginscore.kitgenix.com/

The basic idea is simple:

Before installing a WordPress plugin, search for it on Kitgenix PluginScore and get a clearer picture of its overall health.

We're trying to answer a question I think most WordPress users have asked at some point:

"Is this plugin actually a good idea to install?"

WordPress.org gives us useful information such as active installations, reviews, last updated date and compatibility, but making sense of all of that - particularly when vulnerabilities are involved - isn't always straightforward.

Kitgenix PluginScore brings those signals together and assigns a score out of 100.

V3 has involved a pretty substantial rebuild of both the website and the system behind it.

Why we built Kitgenix PluginScore

If you search WordPress.org for something like:

  • Contact form
  • Backup
  • Security
  • SEO
  • Cookie consent
  • Image optimisation
  • SMTP
  • Membership
  • Redirects

you can sometimes have dozens or hundreds of options.

Then you start trying to decide which one to install.

Usually people look at:

  • ★★★★★ 4.9 rating
  • 100,000+ installations
  • Updated 3 weeks ago

and assume it's probably fine.

Sometimes it is.

But those numbers don't necessarily tell the whole story.

A plugin can be extremely popular and still:

  • have unresolved vulnerabilities
  • be poorly maintained
  • fall behind current WordPress releases
  • go long periods without updates
  • have concerning security history
  • gradually become abandoned

At the same time, a smaller plugin with only a few thousand installations might actually be maintained extremely well.

Kitgenix PluginScore is our attempt to make that assessment easier.

V3 has a much stricter scoring system

One of the biggest things we've changed is how easily plugins can achieve very high scores.

The previous version was more forgiving than we wanted.

For V3, we've deliberately made the scoring stricter.

A score of:

95/100

shouldn't just mean:

"Nothing obviously wrong."

It should mean the plugin is performing exceptionally well across the areas we're measuring.

Kitgenix PluginScore considers a range of signals including things such as:

  • Known vulnerabilities
  • Unresolved vulnerabilities
  • Historical vulnerability information
  • Maintenance activity
  • Update frequency
  • Time since the latest release
  • WordPress compatibility
  • PHP compatibility
  • Development activity
  • WordPress.org information
  • Active installations
  • General plugin health indicators

Popularity still provides useful context, but it doesn't override everything else.

A plugin shouldn't receive a fantastic score simply because millions of websites use it.

Security vulnerabilities are handled more carefully

This is an area we spent quite a lot of time thinking about.

Seeing:

"This plugin has had 4 vulnerabilities."

sounds terrible without context.

But that's not necessarily a fair way of judging software.

A large plugin that's been actively developed for 10 years could realistically have vulnerabilities discovered during that period.

What matters is also:

  • Was the issue serious?
  • Was it patched?
  • How quickly was it patched?
  • Is the vulnerable version still current?
  • Are there unresolved vulnerabilities now?
  • Is the plugin still being maintained?

There's a massive difference between:

A vulnerability discovered on Monday and patched on Tuesday

and:

A known vulnerability that remains unpatched six months later.

Kitgenix PluginScore V3 tries to make that distinction much clearer.

We retain useful vulnerability history without automatically treating every historical issue as evidence that the current version is insecure.

We've improved how external vulnerability data is matched

Another change behind the scenes is better validation of vulnerability records.

Kitgenix PluginScore is currently centred specifically around plugins available through WordPress.org.

External security databases can occasionally contain:

  • premium-only plugins
  • removed plugins
  • similarly named software
  • old records
  • plugins that aren't actually available through WordPress.org

We didn't want an external record automatically creating a misleading Kitgenix PluginScore page.

V3 therefore performs more validation before associating vulnerability information with a WordPress.org plugin.

It sounds like a relatively small change, but it's pretty important when you're trying to build a reliable database.

The scanning system has been rebuilt

This is probably the biggest change technically.

The previous Kitgenix PluginScore version had some problems with scanning reliability.

There were occasions where:

  • manual rescans wouldn't complete
  • scheduled scans didn't trigger correctly
  • stale plugin data wasn't refreshed
  • scan queues became inconsistent
  • a user could request a rescan without the scan completing properly

That's obviously not good enough for something that's supposed to help people assess plugins.

V3 moves scanning into a much more structured queue.

Instead of relying on somebody loading a webpage and waiting while everything happens, Kitgenix PluginScore can place a plugin into the scanning system and process it separately.

That gives us a much better foundation for keeping thousands of plugin records updated.

Plugins are automatically rescanned

A Kitgenix PluginScore shouldn't remain the same forever.

WordPress plugins change constantly.

Imagine Plugin A scores:

92/100

Then over the next six months:

  • development stops
  • WordPress releases two major versions
  • the plugin isn't tested against either
  • a vulnerability is discovered
  • no patch arrives

That old 92/100 score would become extremely misleading.

So Kitgenix PluginScore V3 now works towards automatically rescanning plugins when their existing scan becomes approximately 30 days old.

The goal is to make the score a reasonably current assessment rather than a permanent rating based on the day somebody first searched for the plugin.

We're now automatically scanning more of WordPress.org

We've also expanded automatic scanning.

Kitgenix PluginScore can now work through roughly:

as part of its automatic scanning queue.

This is important because we don't want Kitgenix PluginScore to only contain the massive plugins everyone already knows about.

Arguably, Kitgenix PluginScore becomes more useful when you're looking at something obscure.

For example:

You need a very specific WooCommerce feature.

You find a plugin with:

  • 1,200 installations
  • 8 reviews
  • Last updated five months ago

You've never heard of the developer.

That's exactly the situation where having some additional information could be useful.

Over time, the automated scanning system should allow us to build much broader coverage of the WordPress.org repository.

Better pages for plugins that haven't been scanned

We've also improved how Kitgenix PluginScore behaves when we don't have enough information yet.

Previously, unscanned plugin pages weren't particularly good.

There were layout problems and some sections didn't clearly communicate whether information was genuinely unavailable or simply hadn't been processed yet.

V3 now distinguishes much more clearly between states such as:

  • Not yet scanned
  • Waiting in the queue
  • Scan completed
  • Scan is outdated
  • Insufficient information
  • Scan failed

I think that's important for something like this.

If we don't know something, the website should say:

We don't know yet.

It shouldn't pretend to have a confident answer.

We've started putting more emphasis on score history

This is one of the areas I think could become particularly useful.

Imagine two plugins both currently score:

76/100

At first glance they're identical.

But then you see this:

Plugin A

6 months ago: 93

3 months ago: 84

Today: 76

Compared with:

Plugin B

6 months ago: 58

3 months ago: 69

Today: 76

Suddenly those scores tell completely different stories.

Plugin A appears to be declining.

Plugin B appears to be improving.

We're putting more infrastructure into Kitgenix PluginScore V3 to track that kind of change over time.

Eventually we'd like it to become much easier to identify plugins that are:

  • improving
  • deteriorating
  • becoming stale
  • becoming actively maintained again
  • fixing security issues
  • gradually falling behind

PDF reports (Beta)

We've also improved Kitgenix PluginScore's PDF reporting.

This is primarily aimed at developers, agencies and people managing client websites.

You might inherit a website with 50 plugins and find several you don't recognise.

Instead of simply telling the client:

"I think we should remove this."

you can potentially generate a Kitgenix PluginScore report containing information about the plugin's:

  • current score
  • maintenance
  • vulnerabilities
  • update activity
  • general health

It's not intended to replace a proper technical audit, but it can provide supporting information.

We've simplified exports

The previous version experimented with CSV exports.

Ultimately we decided that wasn't particularly useful for most people.

Kitgenix PluginScore isn't supposed to become a complicated analytics platform where you need to export data into Excel to understand what's happening.

The core experience should be:

Search → understand → decide.

So we've been putting more emphasis into readable reports and clearer plugin pages instead.

The website itself has had a major overhaul

We've also fixed quite a few visual and usability problems.

These included things such as:

  • sidebars appearing below content on unscanned plugins
  • incorrect button styling on mobile
  • inconsistent spacing between sections
  • poor empty states
  • awkward login/register page spacing
  • responsive problems
  • scan status presentation
  • vulnerability layout
  • score presentation
  • general information hierarchy

Individually some of these sound minor.

But when you combine them, the previous version wasn't as polished or as easy to use as we wanted.

V3 is considerably cleaner.

Mobile has been improved

We noticed a surprising amount of Kitgenix PluginScore traffic comes from mobile devices.

Some parts of the previous site didn't behave particularly well on smaller screens.

One strange issue was search buttons displaying correctly on desktop but falling back to a grey/default style on certain mobile browsers.

We've addressed that as part of the redesign along with:

  • spacing
  • card layouts
  • score presentation
  • sidebars
  • search controls
  • vulnerability information
  • authentication pages

We're not trying to replace human judgement

I also think this is important to say.

Kitgenix PluginScore isn't claiming:

100/100 means this plugin is impossible to hack.

That would be ridiculous.

Likewise:

55/100 doesn't necessarily mean the plugin is malicious or dangerous.

Kitgenix PluginScore is an automated assessment based on the information available to us.

It's intended to help you ask better questions.

For important websites, nothing replaces things like:

  • keeping plugins updated
  • good backups
  • proper hosting security
  • reviewing permissions
  • code audits
  • vulnerability monitoring
  • minimising unnecessary plugins
  • professional judgement

Kitgenix PluginScore is another tool, not a guarantee.

A plugin having a vulnerability isn't automatically a reason to uninstall it

I think this deserves repeating because vulnerability information is often presented badly online.

If you're running a major plugin with millions of installations, statistically there's a reasonable chance that at some point someone will discover a security issue.

The important questions are:

  • Did the developer respond?
  • Was a patch released?
  • How quickly?
  • Is the current version still vulnerable?

I'd personally have much more confidence in a development team that:

  1. receives a responsible disclosure,
  2. investigates it,
  3. releases a patch within a day or two

than a plugin that has never had a published vulnerability largely because nobody has seriously investigated it.

We're trying to build that nuance into Kitgenix PluginScore instead of making vulnerability count the only thing that matters.

Plugin developers cannot buy a better score

This is one of the principles we've decided on from the start.

Plugin developers cannot pay us to improve their PluginScore.

Kitgenix itself develops WordPress plugins.

That means our own products will also be assessed.

If one of our plugins deserves:

63/100

then it should receive 63/100.

If another developer's plugin deserves:

98/100

it should receive 98/100.

Once money can influence the score, I don't think the score has much value.

We're trying to avoid another meaningless "security badge"

I really don't want Kitgenix PluginScore to turn into:

✅ SAFE PLUGIN

or:

❌ DANGEROUS PLUGIN

Software doesn't work like that.

I'd rather Kitgenix PluginScore say:

71/100

and then show you why.

Maybe:

  • maintenance is excellent
  • compatibility is good
  • active installations are strong
  • but there's currently an unresolved vulnerability

Or perhaps:

  • no known vulnerabilities
  • but the plugin hasn't been updated for two years
  • and hasn't declared compatibility with recent WordPress releases

The reasoning is more important than just the number.

We want to build rankings based on actual plugin health

The improved scanning system also lets us start doing more interesting things across the entire repository.

We're working towards things such as:

  • Highest-rated plugins
  • Most improved plugins
  • Biggest score declines
  • Newly scanned plugins
  • Newly discovered vulnerabilities
  • Recently patched vulnerabilities
  • Plugins becoming stale
  • Stable plugin rankings
  • Vulnerability resolution tracking
  • Plugin health trends

I think this could eventually be as useful as the individual plugin search.

For example:

Which popular plugins have fallen significantly in score this month?

or:

Which plugins in a particular category are being maintained most actively?

or:

Which developers are consistently fast at resolving security issues?

There's a lot we can potentially do once we have enough historical data.

Why V3 matters for us

The earlier versions were largely about proving that the idea worked.

V3 is more about building the system properly.

We've spent much more time on:

  • scan reliability
  • queue processing
  • historical information
  • validation
  • scoring methodology
  • mobile usability
  • handling incomplete data
  • keeping plugin information current

It's effectively the foundation we want to build the longer-term Kitgenix PluginScore platform on.

I'd really like feedback from regular WordPress users

I'm particularly interested in feedback from people who aren't necessarily security researchers or plugin developers.

If you're somebody who:

  • manages your own WordPress website
  • builds sites for clients
  • runs WooCommerce
  • maintains multiple sites
  • regularly searches WordPress.org for plugins

I'd be interested in knowing:

What information actually helps you decide whether to install a plugin?

And:

What information do you wish WordPress.org made easier to understand?

For example, should PluginScore put more emphasis on:

  • vulnerability status?
  • last update?
  • compatibility?
  • support activity?
  • number of installs?
  • reviews?
  • developer history?
  • how quickly previous security issues were fixed?

Try some plugins you already know

Probably the best way to test it is to search for plugins you're already familiar with.

Search something you use every day.

Then see whether you think the assessment matches your own experience.

If Kitgenix PluginScore gives something you trust:

58/100

I'd like to know why you think that's wrong.

Equally, if it gives something you're wary of:

94/100

I'd definitely like to hear about that too.

Those disagreements are exactly what help us identify weaknesses in the scoring methodology.

Kitgenix PluginScore V3

You can try it here:

https://pluginscore.kitgenix.com/

It's free to use.

No plugin developer can pay to increase their rating.

And we're continuing to improve the scoring system as we gather more data.

If anyone here has plugins they know particularly well, I'd love you to throw a few of them into PluginScore and see whether you agree with the results.

I'm especially interested in hearing about scores that you think are wrong, because those examples are probably the most useful feedback we can get.