Home User profile
tagDiv Member
Christopher is a long time WordPress user. Anything else you need to know is private ;-) I *do not* work for TagDiv, but I've been using their themes since late 2013.
simchris
tagDiv Member

Tables are not normally responsive in WordPress unless you add some CSS.

So, you can simply add CSS like


.table{width:98%}
table{width:98%}

simchris
tagDiv Member

Heh. I thought I did ! Didn’t they add to the ‘best of forums’ tutorials page or something, at least.

Dunno. Have not been around here for awhile, only popped back in due to the subject of the impending ‘guterberg virus’ hitting WP with 5.0 (kidding; I mean the ‘feature’). 😉

Ideally they would pin link to that in the formal documents section – as a “securing your website” for folks reading the docs, as obviously this is kind of a “when setting up your site .. good idea to …” kind of thing.

I actually sent note to the WordPress core folk that they are long past due in adding an actual ‘security’ panel in the main WP admin with quick scan of system (e.g., if WooCommerce can check system why not WP core?), pointers for security best practices, etc. Seriously, how long did it take them to change the default admin account from ‘admin’ when setting up the WP core? Sheesh. And why not an option for a recaptcha at least on the password reset page? (esp in WooCommerce??). Why not an option to disable XMLRPC if not actually using it? Why not option to disable password reset screen entirely for corporate sites? Why not option to enforce superuser for non-multi sites which doesn’t get printed in the JSON and revealed as owner when building pages? The fact WP ‘exposes’ the main admin user building pages in WP, is incredibly stupid. Why not build-in something like the Limit Login Attempts plugin? Argh.

WordPress Security —
“good luck out there” — Automattic.

(sorry… venting … so irritated by WP more interested in Gutenberg than security priority … that should be focus #1, not #5).

🙂

  • This reply was modified 8 years by simchris.
  • This reply was modified 8 years by simchris.
simchris
tagDiv Member

Normally you would have your attachments set to redirect to the post and not load the attachments; WP creates attachment pages for every bit of media you add to a post, much like day, date, month indexes. As long as you have your canonical URL clearly shown in your meta data, in the head (via view page source), you generally don’t need to worry about alternate versions of posts/pages. But again, most folks redirect attachments to the parent page/post.

simchris
tagDiv Member

Did you follow the hardening docs in the wp codex?

There is also a security tutorial i did here awhile back you can search for.

simchris
tagDiv Member

Tip, do not enable gutenberg plugin.

simchris
tagDiv Member

Also, note from your dashboard you will want to install the ‘classic mode’ plugin prior to moving to WP 5.0 as this will allow you to keep all ‘current’ functionality of the post editor and the pagebuilder. You don’t need to activate it until you plan to upgrade to WP 5.0 (although you may wish to install/activate *now* if you have WP auto updates active, which is not a good idea for daily admin folk anyway).


@simion
— Likely there should be a bump in the TD Composer or NP/NM theme update to mention this with a panel added to dashboard ala the new Gutenberg info box?

Gutenberg fundamentally changes the way a post is made, trying to make it a bit like old Quark and PageMaker DTP software, where every element is a ‘block’ — even multiple items on the same page, and it’s a bit wonky as you can end up with blocks you don’t want, and you can’t easily copy/paste the whole shebang into another site, and basic elements like shortcodes, custom fields, etc., might not work at all.

The classic editor will be the best choice for most people using ANY theme built with pagebuilders for the near term. This is for WP 4.9x and up. Not needed for older (and, ahem, insecure versions of WP).

e.g.,
https://wordpress.org/plugins/classic-editor

simchris
tagDiv Member

And of course, in the meantime simply install the classic editor plugin to keep all the current/past functionality of WordPress until Gutenberg is usable.

To learn to use Gutenberg, it’s advisable to setup a test site in a subfolder of your main site like /ttst/ (or /testt/ etc.); install WP there, install TD theme, install Gutenberg plugin; see what happens, without messing with your live site). Super techie folk can also do that via MAMP or whatever, or a subdomain, etc.

Just food for thought. We’re not going to use Gutenberg on our sites as we have NEWS portals, not blogs, so we don’t need to have 20 direction changes in each post, and a nightmare for syndication, losing custom fields, our shortcodes, etc. — a mess.

simchris
tagDiv Member

Check your system status settings in the theme panel to ensure your hosting setup is sufficient. You will generally need to ensure you have enough memory allocated to run both WP, the theme, TD Composer, and WooCommerce, as well as any other extensions.

If you keep having on/off/on/off problems, you may have faulty caching setup, and/or worth checking your site for malware, by running the free Securi online site scan.

simchris
tagDiv Member

Easy to do with css, easy to do with plugins, etc.

simchris
tagDiv Member

Did you update and verify your https site in search console and update your adsense account for https domain?

simchris
tagDiv Member

Disable the lazy load animation in theme panel.

simchris
tagDiv Member

ignore, mark as fixed; this happens when updating/changing theme. Google follows WP and ends up in the /theme/ directory, which it should not do. There is no reason for anybody to go to that location, so it should and always will create an error. This is normal.

Just mark as fixed and get on with life 🙂

simchris
tagDiv Member

Ownership of pages and posts is a part of WordPress, not the theme.

This is why best practices is to have a ‘superadmin’ account for building the site code; then a main admin who creates pages.

So ‘superadmin’ account is ‘admin’ (which should never be admin, and should be something like superjoeadmin.

The pages are then built/owned by another account like ‘joeadmin’ … who is not the superadmin.

You then ‘show’ the author box on the edit page for your ‘pages’ including home page, and then change the ‘author’ to the second level user, not the superadmin.

UPSHOT:
*site manaagement = superadminaccount
*page managemennt = adminaccount /editoraccount

Summary of Roles
Super Admin – somebody with access to the site network administration features and all other features. See the Create a Network article.
Administrator (slug: ‘administrator’) – somebody who has access to all the administration features within a single site.
Editor (slug: ‘editor’) – somebody who can publish and manage posts including the posts of other users.
Author (slug: ‘author’) – somebody who can publish and manage their own posts.
Contributor (slug: ‘contributor’) – somebody who can write and manage their own posts but cannot publish them.
Subscriber (slug: ‘subscriber’) – somebody who can only manage their profile.

This is an old issue of the past decade with WordPress.

simchris
tagDiv Member

Usually you can use the console view and audit functions in Chrome to see sources of any such elements loading. Also note that can be used by ad systems, so best to test pages with any advertisements disabled; similarly any third party plugins like disqus, or social share plugins, jetpack, etc.

simchris
tagDiv Member

I think you need to cut back on things which call ajax in the theme, and also consider using tools like the Limit Login Attempts plugin, and also disable XMLRPC, which can cause overloads.

Note right now that bots are pummeling WordPress sites looking for older versions which are not secure, BootStrap 3 which is not secure, several insecure plugins, and some vulnerabilities in odd versions of PHP, etc.

Generally, the idea is to limit the type of modules being called, don’t use mega menus, don’t use stuff that connects to external sites (JetPack, or “how many likes on xxx”), infinite loading, randomization queries, etc. For instance, no more than two modules on sidebar, disable stuff like “popular posts” and “more from author…” stuff.

All that ‘dynamic’ stuff is a query to the PHP system. Anything with ajax calls has to actually use the WP ajax script … so, your audit needs to start by turning as much off that is glitz and serves no intrinsic purpose, then evaluate what you can live with vs not having dedicated server to manage DDoS and other stuff.

ALSO, just as important: read the “hardening WordPress” section in the docs on WordPress.org, as that can help quite a bit as well.

In our case we needed to run IPtables + Fail2Ban + (D)DoS Deflate – to stop being pummeled by bots, some hitting up to 1800 connections in 5 minutes to a news portal.

simchris
tagDiv Member

Um, ranking impacts traffic; traffic impacts visitors; visitors impact ad views and clicks. Sorry for trying to help. Adsense revenue is dependent on how many visitors actually click ads, less deductions for robots or self-clicks, not on “the theme” or the layout. Generally, you can check your Adsense account for notifications of problems.

And, again, suggest you check your site for “performance” and “best practices” in Lighthouse, as Google will show your site to fewer people if the user experience and page loading for mobile is not up to speed. This impacts visitors, and then revenue.

Good luck!
(I don’t work here; just 23 year webdev and have been using AdSense since it was in BETA.)

simchris
tagDiv Member

That is a paywall plugin, like on some magazine sites. Basically content after first paragraphs hidden until logged in and cookie active. I dont have one to recommend, unfortunately. Kind of need to trial an error it.

  • This reply was modified 8 years by simchris.
simchris
tagDiv Member

you should send request to:
contact@tagdiv.com

also, good to learn to back-up site via FTP prior to any updates, so you can roll back. Also best to update via FTP as “updaters” don’t always work if something going on at same time on your server, not enough resources etc. This also allows you to start keeping backups of each installer version, so you can reinstall if needed, regardless of a site backup. So, each time you download the new version from Themeforest, *keep* the installer, don’t delete it.

simchris
tagDiv Member

Note business hours top right of forum. They answer posts in order received. Older items first. Bumping the post pushes it back, not up. Try clearing cache, resave permalinks, check system requirementd in theme panel. Always make backups so if site not working you can roll back. Disable old plugins, make sure you install main plugins for theme.

simchris
tagDiv Member

Best to audit your pages for errors in chrome and run lighthouse to check best practices. Google has also implemented new speed factor which might affect your rankings if your lighthouse score is under 90.

simchris
tagDiv Member

Best to change some of your layouts to be simpler, using fewer queries, disable xmlrpc, contact host to see what causing overload. Make sure images are highly optimized, turn off images not used, remove plugins and themes not being used.

simchris
tagDiv Member

Also note that Google has been enabling new enhancements to SERPS, based on “speed rating” (so you may see fewer page views if your site not optimized for 90 speed in Lighthouse, or 90+ on the old Pagespeed Insights test).

simchris
tagDiv Member

Need to use a membership plugin.

simchris
tagDiv Member

I use FeedWordPress and have for many years. We have news portals where some stuff originated on the mothership, and selected items then appear on the child sites for regional news. FWP lets you either pull in the full content as new posts and/or have the posts point at the original source, but still be used in local indexes or modules. We use it with Auto Post Thumbnail Pro to make local thumbnail copies from the external image.

Viewing 25 posts - 926 through 950 (of 9,335 total)