Stick around ‘til the end. We’ve got a four-legged percussionist who’s stealing hearts and drumsticks.
In today’s edition:
- There’s a new WordPress feature that could make your site feel lightning-fast… or break it completely. The kicker? It’s already turned on.
- Ottokit left a door open to privilege escalation and hackers everywhere said “thank you.” If you haven’t updated yet… go do that. Like, now.
- The WordPress Contribution Health Dashboard is sick, not in the cool way. It needs more devs. Are you the data doctor it’s waiting for?
Hot Off The Presses: What’s New?
You know that feeling when you make “just a tiny CSS tweak” and suddenly your whole site looks like something Picasso painted after a very absinthe-heavy lunch?
Whether you’re gonna spend hours meticulously putting everything back into alignment, or throw your hands up and call it “Avant Garde Cubist Vibe Coding” – it might be time to take a break.
Good thing you’ve just opened DEV. 😌
Let’s jump into what’s new in WordPress, shall we?
The Contribution Health Dashboard Needs an Infusion of Skilled Devs
Hari Shanker, long-time WordPress contributor and data whisperer, popped into the WP Tavern podcast last week to shine a light on the experimental WordPress Contribution Health Dashboard project designed to help team leads and contributors figure out who needs what, and where the community’s collective attention should go. Think: triage charts for open-source labor.
The idea? Brilliant. The execution? Well… let’s just say the patient is stable but not exactly doing jumping jacks.
Turns out, building a sleek, data-rich dashboard that surfaces meaningful insights across dozens of global contributor teams… requires more than vibes. It needs tooling. Infrastructure. And, you guessed it, humans who can code the damn thing.
Hari’s diagnosis: a serious shortage of contributors with data skills. Especially those who can wrangle metrics, interpret them in useful ways, and help turn dashboards from static spreadsheets into community lifesavers.
The dream? A beautiful, accessible visual dashboard that helps every contributor make the most of each single contribution hour.
So, if you know your way around a spreadsheet, SQL query, or data visualization tool, now’s your time to shine.
👉 Check out the full conversation on WP Tavern Ep. 168.
WordPress 6.8 Is Now Reading Your Mind (Sort Of)
WordPress 6.8 introduced Speculative Loading, a new performance feature that preloads links before visitors even click on them. Yep, your site is now out here making assumptions like an overenthusiastic dog assuming every doorbell is for them.
Here’s the idea: based on user behavior, WordPress preloads links that it thinks visitors might click next, so pages load faster if they actually do. It’s like your site saying, “Oh, you’re hovering? Let me just start cooking that page for you, no pressure.”
WP Core simply adds a bit of JSON to your pages, so supportive browsers such as Chrome and Edge can preload pages and offer near-instant transitions, and non-supportive browsers can simply ignore it.
It’s clever. It’s fast. It’s… enabled by default whether you asked for it or not. And while speculative loading can absolutely improve perceived performance (especially on slower connections), it’s not without quirks.
Some devs are worried about unnecessary server load (especially on shared hosting), broken analytics, or just the general creepiness of your site trying to guess your next move. Simon Harper from Loop WP points out that it could cause issues with other plugins and their interactions with Core, such as WooCommerce for example.
Want to turn it off? There’s a video for that. But for most sites, this feature could be a solid performance win.
Speaking of performance wins: we just dropped Smush 3.19, which includes LCP preloading for your Largest Contentful Paint images. Your most important image will now show up faster, boosting your PageSpeed score considerably.
So between WordPress preloading pages and Smush preloading your heaviest images, your site can basically become that kid in school who always knew the answer before the teacher even finished the question.
Just don’t make it preload your newsletter archive. That thing’s a beast.
What do YOU think of Speculative Loading? Let us know in the comments!
👉 Helpful Resource: Want to know how to manage Speculative Loading on your website the right way? WP Explorer put together this incredibly useful guide. Check it out!
Hackers Looooove Outdated Plugins (And OttoKit Just Proved Why)
The OttoKit plugin (formerly SureTriggers) is back in the headlines, with the second major bug found in it this month. It’s not great news for the 100,000+ WordPress sites using the plugin. In fact, it’s the kind of terrifying flaw that makes your site vulnerable to full takeover. Fun.
The bug is known as an “incorrect privilege assignment flaw” that allows hackers to sneak in, create a new account and assign themselves the administrator role faster than your uncle finds conspiracy theories on Facebook.
The good news? It’s already patched. The bad news? You have to actually update it.
Ottokit implemented a patch for the vulnerability in version 1.0.83, so if you’re still running an earlier version, you might as well roll out a red carpet for hackers.
Let this be your friendly reminder: keeping your site’s plugins updated is not optional. And if you’re managing multiple sites (or just have better things to do than babysit changelogs), Automate in The Hub can handle all your updates for you, without breaking stuff. (So, you know, you don’t find out that your site’s in trouble via your client’s angry midnight Slack message.)
Oh, and in case your site has already been compromised (no judgment, it happens to the best of us) our new monthly Malware Removal service has your back.
Stay safe out there.
👉 Here’s the full scoop from Patchstack on the vulnerability.
Mind Bloggling Facts & Stats
- In April, contributors to the WordPress Core Team came from 19 different countries! These included India (40 contributions), the U.S.A. (35), Germany (7) and Japan (7). A pretty international bunch! (Source)
- According to WPapac, a new community for WordPress professionals in Asia Pacific, 42% of individual contributors to WordPress 6.8 came from Asia Pacific. (Source)
- Aaron Jorbin took the lead on the WordPress 6.8.1 maintenance release and contributed a total of 80 Trac tickets, 28 core commits and four bug scrubs across March and April. Nice work, Aaron! (Source)
- On Global Accessibility Awareness Day (May 15th) 86 amazing folks pledged a total of 382 hours to improve accessibility in WordPress. Pretty cool to see who took part, and what they worked on. Psst… Maybe this is your cue to set aside a few hours to work on accessibility too! (Source)
Blogs & Resources You Shouldn’t Miss
Jono Alderson says your content is trash. But like, in a helpful way. Here’s how to untrash it.
Jamie Marsland says AI won’t steal your job, it’ll give you a better one. Bold claim. Wanna fight him or hear him out?
Post Status picked up WP Speakers – a one-stop shop for confident nerds with PowerPoints.
Wanna stay relevant in 2025? GravityKit made a WordPress tech cheat sheet so you don’t embarrass yourself at the next WordCamp.
Raising your rates? Here’s how to tell your clients without spontaneously combusting from anxiety. 😰
Anders Norén built a full block theme over a weekend. What did you do? Watch Netflix?
Closing tickets is the unsung hero of productivity. Here’s how to do it without the guilt.
Coffee Break Distractions
WordPress Women’s Day was straight fire. These women are out here changing the game!
Just when you think your UI is idiot-proof… (Spoiler, it’s not.)
Turn the tables on a classic with Reverse Pac-Man: The ghost hunter has become the hunted.
Screw the career ladder. Michelle’s making a casserole! (Honestly, that sounds a lot better…)
Hey Font Tester Browser Extension… the font on your landing page is MOONING ME! 🍑
And finally…
Found this interesting? Forward it to someone who you think might also love it! 💗