WPBeginner Spotlight 26: Form Analytics, More AI Tools, and Smarter SEO Monitoring

The main theme of this month’s WordPress news is measurement. Most of what shipped in July shows you something that your site was already doing without telling you. WPForms can now show which form field people abandon, and AIOSEO can tell you the day a plugin sets your homepage to noindex. On top of that, WPVibe crossed 5,000 installs, and HelpJet launched as a new AI support chatbot. Let’s take a look at what’s new in the world of WordPress for July. WPBeginner Spotlight brings you a monthly roundup of the most important WordPress news, updates, and community happenings. 📅✨ Got something to share? Whether it’s a new product launch, a significant update, or an exciting event, reach out to us through our contact form, and your news could be featured in the next edition! WPForms Launches Built-In Analytics to Track Form Performance If visitors abandon your WordPress forms before submitting them, you’re usually left guessing what went wrong. Until now, there was no easy way to identify where people dropped off or why. WPForms 2.0 changes that with WPForms Analytics, a built-in form tracking suite that lets you see where users abandon your forms right from your WordPress dashboard. The most powerful feature is the field-level analytics. A field-by-field table shows interactions, time spent, errors, and abandonment for every part of your form. That tells you the exact point where people give up. That might be a phone number field people do not want to fill, or an address field that throws errors. Once you know which one it is, the fix is usually simple: remove the field, reword it, or make it optional. Your All Forms page now shows views, entries, and conversion rate for every form. Each form also gets its own dashboard, with filters for the last 7, 30, or 90 days. There is a built-in AI chat as well. You can ask it what is hurting your conversions, and it reads your form data and tells you what to fix first. WPVibe Passes 6,000 Installs and Adds Page Builder Integrations, AI Code Snippets, and Memory WPVibe, the WordPress MCP server built by SeedProd, has crossed 6,000+ active installs on WordPress.org. WPVibe lets you manage your WordPress site by simply chatting with your favorite AI assistant. Instead of clicking through admin screens, you describe what you want, and the AI does it for you. It works with Claude, ChatGPT, Codex, Cursor, and more. Here is what arrived in the last few weeks: Page builder integrations: Your AI assistant can now automate tasks in Elementor, Divi, SeedProd, and Beaver Builder. AI code snippets: Ask AI to write custom code for your site. That removes one of the most intimidating parts of WordPress for non-developers. Memory: WPVibe remembers how you like to run your site, so you don’t have to repeat yourself. AI recipes in your dashboard: WPVibe suggests ready-made automation ideas picked for your site. Related: How to connect AI agents to your WordPress site We believe that WPVibe is one of the more practical answers to the question of what AI can actually do for WordPress users. It handles the repetitive admin work, and you stay in control. WordPress Ships Major Security Fixes WordPress 7.0.2 came out on July 17 as a security release that fixed one critical and one high severity issue. Because of the severity, the WordPress.org team turned on forced updates for affected sites, so many sites are already patched. The two security issues allow code to run on a default install without anyone logging in. Both are now in CISA’s catalog of known exploited vulnerabilities, so it is worth confirming your version rather than assuming. Head over to Dashboard » Updates and check the version you are on. If it reads 7.0.2, 6.9.5, or 6.8.6, then your website is fine. Otherwise, we recommend updating your website now. 7.0.2 also includes the earlier 7.0.1 maintenance release and its 31 bug fixes across Core and the Block Editor, so a single update gets you both. HelpJet: The AI Chatbot That Answers Your Customers’ Questions in Seconds HelpJet is a new AI support chatbot built by the team at HeroThemes, a WPBeginner Growth Fund company. It learns your help documentation and answers customer questions from it, 24/7, without needing anyone on your team to be online. Setup is simple. You add your help articles, URLs, and even private standard operating procedures, and the chatbot is ready in about five minutes. From there, it takes the repetitive questions off your team’s queue. Anything it cannot answer is passed to a human. HelpJet then learns from that reply, so it can handle the same question next time. On a WooCommerce store, it can also read your product data, including variations, stock levels, and shipping and tax rules. So a shopper asking about a specific product gets a real answer, not a link to your policy page. You can customize the chatbot and display it with no code required. It also runs on Shopify and Squarespace. For more details, see our HelpJet announcement post. AIOSEO Introduces SEO Alerts: An Early Warning System for Site Issues Serious SEO problems rarely announce themselves. For example, a plugin update can quietly set your homepage to noindex, which tells search engines not to list it. Or your robots.txt file may stop responding after a server migration, and Google pauses crawling until it can read the file again. To solve this, All in One SEO, one of the most popular WordPress SEO plugins, has introduced SEO Alerts, which checks three things every hour: whether your homepage is set to noindex, whether your robots.txt file is reachable, and whether your XML sitemap is loading. You can receive alerts by email or Slack. You configure it once, and AIOSEO monitors your site from there, so you hear about a problem within the hour instead of weeks later. SEO Alerts is free on every plan, including the free AIOSEO Lite version. AIOSEO has also introduced

Matt: Possible Futures of Happiness

At Automattic, we don’t have customer service or support, we have Happiness Engineers. There’s also a #ceo Slack channel where anyone can drop in and request a meeting, which my esteemed colleague Damianne President did, and this morning we had an interesting chat that set my mind racing about how we might engineer happiness in the future. One overriding assumption: Personal agents will trounce company agents in most cases. Your personal agent can — or soon will — know all your history, your calendar, your email, your preferences, and your photos, and it speaks your language. So much time is wasted in traditional support trying to see through the customer’s eyes, or authenticate them. That goes away, but watch your thinking! It’s so easy to fall into the mental model trap of legacy chatbots and data models. As a company, your website, your WordPress, documentation, tutorials, menus, manuals need to be amazing and up to date. That’s the source of truth, and an agent will read all of it! The interface and APIs remain because that’s useful to both human visitors and the agents. Whenever possible, make support public. More blogs and bbPress. I actually weep a little when I think of how many beautiful words are written by our Happiness Engineers that are only ever seen once in a chat box or email thread. My goal with our products is that support is radically available, and you almost never have to use it. If you’re in a support role, I think you can pick a lane based on where you get energy. If you love looking at screens, I think there’s a future where customer service wizards are watching over an Iron Man-like interface, armies of chat bots talking to people, where they can see how they’re going and intervene or nudge them as needed. There’s a ton of work in tuning agents and interactions. If people recharge you, I actually think this will be the greatest era. All of the basic, mechanical stuff will be automated, but I think human connection will be what economists call a Veblen good, more in demand even as it is more expensive. I think Happiness Engineering in the future will look a lot more like community building. A bot can’t host a meetup or a WordCamp. I was the biggest Waymo fanboy, but this year with lots of trips to and from hospitals with Om I found myself craving human connection and used Uber more than ever. (It also gave me a chance to practice the one repeatable way that money can buy happiness, which is keeping a couple Benjamins in your back pocket and surprising people with them.)

Gutenberg Times: WordPress 7.1 Source of Truth

Welcome to the Source of Truth for WordPress 7.1! Before you dive headfirst into all the big and small changes and pick your favorites, make sure to read these preliminary thoughts about this post and how to use it. If you have any questions, leave a comment or email me at pauli@gutenbergtimes.com. A huge “Thank you” to Anne McCarthy, Justin Tadlock, Isabel Brison, Adam Silverstein, Ramon Dodd, Andrew Serong, Hans-Gerd Gerhards, Marin Atanasov, Krupa Nanda, Aaron Robershaw, Ben Dwyer, Brent MacKinnon, Ashar Fuadi, and a lot more. It still takes a village. Also huge respect to the whole release squad on getting WordPress 7.1 over the finish line. Estimated reading time 34–51 minutes at 7,991 words Table of Contents Changelog Important note/guidelines Overview Resources Assets  Tags Priority Items for WordPress 7.1 Responsive styles for blocks [theme builders] [site admin][end user] Viewport breakpoint customization Interactive states styling (hover, focus) Media editor modal and free-form image cropper [end user][site admin] Client-side media processing improvements [developer][site admin][enterprise] Icons now inherit color, and the Icons API takes shape [theme builder][plugin author][developer][enterprise] For developers: Registering more collections Admin Bar everywhere  [all] New Blocks [all] Playlist block Tabs block Improved Blocks and Block handling Block transforms: preview first, convert faster [end user][site admin] Combine gradient and image backgrounds [end user] [theme builder][site admin] Cover Block: control video embed providers [theme builder][plugin author][enterprise][developer] Gallery and the attached images workflow in the Media Library [end user][site admin] Image Block: Mark as decorative toggle [end user][site admin] Login/out Block Improvements [theme builder][site admin][developer] Navigation Block and Link Creation [theme builder] [site admin][end user] Search block Styling[theme builder] [site admin][end user] Query block [theme builder] [site admin][end user] General quality of life improvements.  Pattern editing experience improvements [theme builder] [site admin] [developer]  Block Width and Layout Controls [theme builder] [site admin] [developer] Link Control and Preview Enhancements [theme builder] [site admin] [developer] Additional CSS Validation [theme builder] [site admin] [developer][end user] Block Editor Attribute Handling [theme builder][developer] Image handling improved [end user][site admin] Post Template Layout Improvements [theme builder][site admin] Post Title Block Enhancements[site admin][end user] Block Inserter Enhancements [site admin][end user] Editor enhancements Notes move toward a full commenting workflow [end user][site admin][developer][enterprise] Dedicated Identity section [site admin][theme builder][end user] Visual revisions improvements [site admin][end user][theme builder] Apply Globally now with review panel Admin / Workflow updates Organized command palette [all] Change a comment’s parent from the Edit Comment screen [end user][site admin][enterprise] See an excerpt of posts without titles [end user][site admin] On This Day dashboard widget[end user][site admin] Media Library: infinite scrolling is back on by default, with a per-user opt-out [end user][site admin] Developer Goodies [developer][theme builder][plugin author][enterprise] Post editor iframe now always on Global Styles and theme.json  Text Shadow support for theme.json Text-Align Block Support Migration Block Visibility Block Supports: CSS variables by feature selector A minimum-width option for block dimensions Design System Theme Provider  Admin color schemes in Site Editor Mix static HTML with editable blocks Block Bindings for list-items and inner blocks Connectors authentication improvements Blocks package stabilizes two experimental functions Accessible tooltips and toggle tips API Filtering Site Editor screens Changelog Any changes are cataloged here as the release goes on. July 30, 2026 – First edition. July 31, 2026 Added Apply Globally now with review panel Added Filtering Site Editor screens Important note/guidelines Try not to just copy and paste what’s in this post since it’s going to be shared with plenty of folks. Use this as inspiration for your own stuff and to get the best info about this release. If you do copy and paste, just remember that others might do the same, and it could lead to some awkward moments with duplicate content floating around online. Each item has been tagged using best guesses with different high-level labels so that you can more readily see at a glance who is likely to be most impacted.Each item has a high-level description, visuals (if relevant), and key resources if you would like to learn more. Overview WordPress 7.1 rounds out the block editor’s styling controls and makes working with media noticeably smoother. Long-requested features let you style how blocks look across three screen sizes and in interactive states like hover and focus — all without writing custom CSS. The admin experience becomes more personal, too, following you with your own color scheme and toolbar across every screen. Handling images gets a considerable upgrade, too. The new media editor modal brings free-form cropping, rotation, and metadata editing into one workflow, and client-side media processing makes uploads faster and more resilient, with broader format support and better-optimized files. The new Playlist and Tabs blocks enrich the layout options available out of the box and make for more creative information presentation. In the same realm fall the expanded Icon API with custom icon collections, dynamic galleries, and background gradients for more blocks. The unification of WP Admin and the block editors progresses as well: the editors now respect your admin color scheme, and the admin bar stays with you on every screen — including the editors and the front end. A new “On This Day” Widget connects you to your site’s history. While real-time collaboration has been punted to a future WordPress version, the asynchronous collaboration in Notes took real steps forward with inline notes on partial text selections, @mentions, rich text formatting, and multiple notes per block. Beyond the headliners, core blocks receive many quality-of-life improvements and bug fixes to make editing content in WordPress streamlined, consistent, and fast — and developers get an expanding set of APIs to build on. Resources Help Test WordPress 7.1 \ FieldGuide + Dev Notes are scheduled to be published August 5. Roadmap to 7.1 This release consists of features from the Gutenberg plugin version 22.7 – 23.6. Here are the release posts of those plugin releases: 22.7 | 22.8 | 22.9 | 23.0 | 23.1 | 23.2 | 23.3 | 23.4 | 23.5 | 23.6 Later Gutenberg releases contain bug fixes, backported to WordPress 7.1.

Open Channels FM: Signal – Issue 18

Talk about personal journeys in web development, the complexities of fame, and the benefits of open source, emphasizing enriching content options for listeners beyond traditional podcasts.

WordPress.org blog: WordPress 7.1 Beta 4

WordPress 7.1 Beta 4 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta 4 You can test WordPress 7.1 Beta 4 in any of the following ways: WordPress Beta Tester Plugin Install and activate the WordPress Beta Tester plugin on a WordPress install. Select the “Bleeding edge” channel and “Beta/RC Only” stream. Direct Download Download the Beta 4 version (zip) and install it on a WordPress website. Command Line (WP-CLI) Use this WP-CLI command: wp core update –version=7.1-beta4 WordPress Playground Use a 7.1 Beta 4 WordPress Playground instance to test the software directly in your browser. No setup required-just click and go! The scheduled final release date for WordPress 7.1 is August 19, 2026. The full release schedule can be found here. Your help testing Beta and RC versions is vital to making this release as stable and powerful as possible. Thank you to everyone who contributes by testing! Find out what’s new in WordPress 7.1: Read the Beta 1 announcement for details and highlights. How important is your testing? Testing for issues is a critical part of developing any software, and it’s a meaningful way for anyone to contribute – whether or not you have experience. Details on what to test in WordPress 7.1 are available here. If you encounter an issue, please share it in the Alpha/Beta area of the support forums. If you are comfortable submitting a reproducible bug report, you can do so via WordPress Trac. You can also check your issue against this list of known bugs. Curious about testing releases in general and how to get started? Follow along with the testing initiatives in Make Core and join the #core-test channel on Making WordPress Slack. What’s in WordPress 7.1 Beta 4? WordPress 7.1 Beta 4 contains more than 114 updates and fixes since the Beta 3 release, including 51 in the Editor and 63 in Core. Each beta cycle focuses on bug fixes, and more are on the way with your help through testing. You can browse the technical details for all issues addressed since Beta 3 using these links: GitHub commits for 7.1 since July 22, 2026 Closed Trac tickets for 7.1 since July 22, 2026 Beta 4 brings a round of fixes that make the editor smoother to work with. Notes now stay reliably tied to the passage they refer to, and tagged people are displayed cleanly and clearly. A Beta 4 haiku Testers lend their eyes,edge cases hide in plain sight—Patch, rebuild, refine. Props to @krupajnanda for preparing this post and @annezazu, @wildworks, @amykamala for proofreading and review. Join us for the launch of WordPress 7.1 at WordCamp US 2026, August 16–19.

WPTavern: #227 – Maciek Palmowski on Testing Secure WordPress Hosting: Does the Marketing Match Reality?

Transcript [00:00:19] Nathan Wrigley: Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley. Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in this case, testing secure WordPress hosting, does the marketing match the reality? If you’d like to subscribe to the podcast, you can do that by searching for WP Tavern in your podcast player of choice, or by going to wptavern.com/feed/podcast, and you can copy that URL into most podcast players. If you have a topic that you’d like us to feature on the podcast, I’m keen to hear from you and hopefully get you, or your idea, featured on the show. Head to wptavern.com/contact/jukebox, and use the form there. So on the podcast today we have Maciek Palmowski. Maciek is based in Poland and works at Patchstack, one of the companies in the WordPress ecosystem dedicated specifically to security. At Patchstack, Maciek collaborates with other security professionals on industry reports, bug bounty programmes, and solutions for agencies, product owners, and hosting companies aiming to secure their client sites. I met up with Maciek at WordCamp Europe, and we discussed his presentation there. It examined the claims of secure hosting made by many WordPress hosting providers. He describes how Patchstack set out to test these claims with real world penetration testing, using 30 known plugin vulnerabilities across multiple hosts. Employing standardised methodologies and validating their results independently. The findings are sobering. The majority of WordPress specific attacks still get through, and there’s a significant gap between the marketing hype and real protection. The conversation starts with Maciek’s background, and how his journey in the WordPress security space led to a focus on the promises made by hosts. From there, the discussion gets into the research approach, the selection of well-known vulnerabilities, consistent testing across different hosting environments, and the surprising result that even hosts with identical security tooling produce drastically different outcomes, showing it’s not just about the tools you use, but how you use them. We talk about the Swiss cheese model of security, every layer will have holes, so you need multiple overlapping defences, and honest communication from hosts about their limitations. We also explored whether an industry-wide standard, or badge, for secure hosting is feasible or even desirable, given how easy it is for strong marketing claims to outpace reality. AI also enters the conversation, increasing both the speed and sophistication of attacks, and making patching, and processes, even more important, especially as the volume of vulnerabilities continues to rise and the time to exploitation drops. If you’re interested in understanding what secure hosting really means, how to ask intelligent questions of providers, and the realities of WordPress security in 2026, this episode is for you. If you’d like to find out more, you can find all of the links in the show notes by heading to wptavern.com/podcast, where you’ll find all the other episodes as well. And so without further delay, I bring you Maciek Palmowski. [00:03:56] Maciek Palmowski: I am joined on the podcast by Maciek Palmowski. Hello Maciek. Perfect. You did great. [00:04:01] Nathan Wrigley: For some reason, your name has got into my head. A lot of the people that I interview, I struggle with their name, and I continue to struggle, but for some reason, I established many years ago that was how to say your name. And I think I’ve done it correctly ever since then. [00:04:16] Maciek Palmowski: Yes you did. You’re almost having the typical Polish accent, so you’re doing great. [00:04:21] Nathan Wrigley: So we are at WordCamp Europe, which is in Krakow, or Krakow, I don’t know how. [00:04:26] Maciek Palmowski: Krakow. [00:04:27] Nathan Wrigley: Thank you, that was good. And the reason Maciek is correcting my pronunciation is because Maciek is actually from Poland, which I suppose means that this is a bit of a, well, it’s like a home game to you. [00:04:37] Maciek Palmowski: In a way so, but it’s also like a bit of a shame because I do like travelling when WordCamp Europe’s are happening. And, you know, just hopping on the train and going to Krakow, it was like a, I mean it’s cool because, yeah, the venue’s amazing, everything is great, but still I’m staying home, so yeah. [00:04:53] Nathan Wrigley: Yeah, mixed feelings. So Maciek has done, or is going to do a presentation at WordCamp EU. Have you done it yet? [00:05:02] Maciek Palmowski: I will do it tomorrow. [00:05:04] Nathan Wrigley: Okay. And are you all set, are you one of these like really prepared people that has all the slides done, or are you last minute? [00:05:11] Maciek Palmowski: Everything is ready. I already did one version of it at the Checkout Summit in Palermo, so. [00:05:17] Nathan Wrigley: Oh I see. So you’ve had a sort of dry run of elsewhere. [00:05:19] Maciek Palmowski: Of course. [00:05:20] Nathan Wrigley: Excellent. So the presentation, which is going to be the focus of today’s conversation, is called Testing the promise, does secure hosting deliver? And I may as well read the blurb because it was a reasonably short one. So it says, secure hosting, in quotes, is everywhere in WordPress. What does it actually protect against? We put this claim to the test with real penetration testing. 30 known vulnerabilities, multiple hosting providers, standardised methodology, validated by independent observers. The findings reveal a critical gap between marketing and reality. WordPress specific attacks succeed most of the time. That’s quite an alarming sentence. This talk shares the complete results and explains why generic security fails. So, we’ll get into that in a moment. But as with all people, when I’m talking to them about security, I guess it’s good to establish who you are, and what your credentials are and what you’ve done, and how is it that you get to talk about security with authority. So over

Open Channels FM: Why Real-Time Threat Detection Matters for Website Security

Much of the conversation around web security centers on preventative measures and layers of defense, but there’s a new front line that deserves focused attention: real-time threat detection at the runtime level. With attacks now happening faster and at greater scale thanks to AI, the ability to identify and block malicious activity as it unfolds […]