August 31

How to Update WordPress with Automation

The Ultimate WordPress Update Checklist

When it comes to placing the “blame” for this overabundance of WordPress security breaches, it’s not fair to point to developers who built or now maintain WordPress or its third-party integrations. In fact, most WordPress breaches can be traced back to user error.

Did you know that over 70% of WordPress installs currently do not run on the most current and secure version of the platform? These WordPress updates are released for a reason–WordPress now even automates minor security upgrades in order to ensure that users’ sites are safe from those known vulnerabilities.

Then there’s the matter of plugins and themes. 54% of all WordPress vulnerabilities can be traced back to plugins and 14% to themes. Unless there is a serious security issue detected within one of these, WordPress will not force an automatic update for all users. They’ll instead rely on developers to create a patch and send out an update notification.

Ultimately, it comes down to you remaining cognizant over your WordPress website, monitoring for updates as soon as they become available, and then implementing them right away. This is the only way to keep WordPress as safe as possible.

How to Update WordPress with Automation

In 2013, WordPress was kind enough to gift us with automated updates. These are not universally applied, however, and will only occur with minor releases and the infrequent plugin or theme update that urgently needs pushing out. All major releases and other plugin and theme updates still need to be processed by you.

If you’d like to spare yourself the responsibility of doing that–without compromising your site’s safety–you can automate these updates. Here’s what you’ll need to do:

1. Schedule Backups

Even if you’re not manually processing each update, it’s still important to have regular backups of your site saved. You can do this by using a backup and restore plugin. This will ensure that you have something to roll back to in case something goes wrong during one of those automated updates.

2. Automate with a Plugin

While you could log into WordPress each day and watch for the little notification at the top of the dashboard that says you have updates waiting, you can instead use a plugin to handle the work for you. Easy Updates Manager is a free plugin that you can use either on a single WordPress website or for a full Multisite network.

Easy Updates Manager

Once you have the plugin installed, you’ll need to configure the settings for it.

The dashboard (pictured above) will give you easy toggle on/off access to automating core, plugin, and theme updates for your site.

Pay special attention to the General Settings tab as well. While the top part of the page gives you the ability to set universal controls over what is automated and what’s not, the bottom part (Notifications and Miscellaneous) you might find particularly useful as well.

And don’t forget to look at Advanced Settings before you save and close up the configuration page. If you have multiple users who have access to your site, but you don’t want them to have control over these settings, you can adjust access levels there.

3. Or Automate Your Workflow

Rather than rely on one plugin to handle backups and one plugin to handle updates, why not use one tool that consolidates all that automation into one? ManageWP is a fantastic option for this as it enables you to:

ManageWP also comes chock full of security features to help you better maintain the overall health and safety of your website without breaking a sweat.

As a WordPress maintenance service provider, we’ve found ManageWP’s solution to be incredibly valuable to our operations and workflow. With the enhanced visibility, convenience, and control we now have into all our websites’ performance, security, and pending updates, we’ve been able to focus on growing our business (by 39%, in fact) rather than on trying to keep track of everything we have to do for each of our current clients.

August 31

15 Easy Ways To Speed Up WordPress

speedup banner

 

Why WordPress Site Speed Matters

When a person lands on your site for the first time, you only have a few seconds to capture their attention to convince them to hang around.

Get ready to lose sleep at night: according to a report by the Microsoft Bing search team, a 2-second longer delay in page responsiveness reduced user satisfaction by 3.8%, increased lost revenue per user by 4.3%, and a reduced clicks by 4.3%.

If your site takes too long to load, most people are gone, lost before you even had a chance.

Not only that, but Google now includes site speed in it’s ranking algorithm. That means that your site’s speed effects SEO, so if your site is slow, you’re now losing visitors from impatience and reduced rankings in search engines. Yikes.

Let’s fix that.

How To Speed Up WordPress

As a side note, these are not ordered by importance or any criteria, I’ve just gathered everything I’ve learned around how to speed up WordPress page loads and listed them all here.

I guarantee that using even a few will help speed up your site.

1. Choose a good host

When starting out, a shared host might seem like a bargain (“Unlimited page views!”). It comes at another cost: incredibly slow site speed and frequent down time during high traffic periods.

If you plan on publishing popular stuff, you’re killing yourself by running your WordPress site on shared hosting.

The stress of your site going down after getting a big feature is enough to create a few early gray hairs: don’t be a victim, invest in proper hosting.

The only WordPress host I continually recommend is:

✓ WP Engine managed WordPress hosting

💡 Note: Above is my personal referral link which provides a small discount (and a small commission to me) if you use it. I only recommend products I personally use and companies I support.

My sites are always amazingly fast, never have downtime when I get huge mentions (like when I was featured on the Discovery Channel website), and the back-end is very easy to use.

Last but not least, their customer support is top notch, which is a must when it comes to hosting. Take it from someone who’s learned that the hard way. The staff is friendly, patient, and well-versed on the ins and outs of WordPress. They’ll be your safety net for any problem that may arise.

2. Start with a solid framework/theme

You might be surprised to here this, but the Twenty Fifteen “framework” (aka the default WP theme) is lightweight and quite speedy.

That’s because they keep the “guts” simple; compare that to bloated frameworks which have tons of features that you will never use, slowing your site to a crawl.

From my experience, the fastest loading premium framework is definitely the Thesis Theme Framework. It surpasses the basic WordPress themes by being far easier to customize.

It’s an incredibly solid framework that won’t slow you down with excess plugins or custom edits. Make the changes right from the theme and avoid bloat, hoorah!

3. Use an effective caching plugin

WordPress plugins are obviously quite useful, but some of the best fall under the caching category, as they drastically improve page loads time, and best of all, all of them on WordPress.org are free and easy to use.

By far my favorite, bar none, is W3 Total Cache, I wouldn’t recommend or use any other caching plugin, it has all of the features you need and is extremely easy to install and use.

Simply install and activate, and what your page load faster as elements are cached.

4. Use a content delivery network (CDN)

All of your favorite big blogs are making use of this, and if you are into online marketing using WordPress (as I’m sure many of my readers are) you won’t be surprised to here that some of your favorite blogs like Copyblogger are making use of CDN’s.

Essentially, a CDN, or content delivery network, takes all your static files you’ve got on your site (CSS, Javascript and images etc) and lets visitors download them as fast as possible by serving the files on servers as close to them as possible.

I personally use the Max CDN Content Delivery Network on my WordPress sites, as I’ve found that they have the most reasonable prices and their dashboard is very simple to use (and comes with video tutorials for setting it up, takes only a few minutes).

There is a plugin called Free-CDN that promises to do the same, although I haven’t tested it.

5. Optimize images (automatically)

Yahoo! has an image optimizer called Smush.it that will drastically reduce the file size of an image, while not reducing quality.

However, if you are like me, doing this to every image would be beyond a pain, and incredibly time consuming.

Fortunately, there is an amazing, free plugin called WP-SmushIt which will do this process to all of your images automatically, as you are uploading them. No reason not to install this one.

6. Optimize your homepage to load quickly

This isn’t one thing but really a few easy things that you can do to ensure that your homepage loads quickly, which probably is the most important part of your site because people will be landing there the most often.

Things that you can do include:

  • Show excerpts instead of full posts
  • Reduce the number of posts on the page (I like showing between 5-7)
  • Remove unnecessary sharing widgets from the home page (include them only in posts)
  • Remove inactive plugins and widgets that you don’t need
  • Keep in minimal! Readers are here for content, not 8,000 widgets on the homepage

Overall, a clean and focused homepage design will help your page not only look good, but load quicker as well.

7. Optimize your WordPress database

I’m certainly getting a lot of use out of the word “optimize” in this post!

This can be done the very tedious, extremly boring manual fashion, or…

You can simply use the WP-Optimize plugin, which I run on all of my sites.

This plugin lets you do just one simple task: optimize the your database (spam, post revisions, drafts, tables, etc.) to reduce their overhead.

I would also recommend the WP-DB Manager plugin, which can schedule dates for database optimization.

8. Disable hotlinking and leeching of your content

Hotlinking is a form of bandwidth “theft.” It occurs when other sites direct link to the images on your site from their articles making your server load increasingly high.

This can add up as more and more people “scrape” your posts or your site (and especially images) become more popular, as must do if you create custom images for your site on a regular basis.

Place this code in your root .htaccess file:

disable hotlinking of images with forbidden or custom image option
RewriteEngine on
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http(s)?://(www\.)?sparringmind.com [NC]
RewriteCond %{HTTP_REFERER} !^http(s)?://(www\.)?google.com [NC]
RewriteCond %{HTTP_REFERER} !^http(s)?://(www\.)?feeds2.feedburner.com/sparringmind [NC]
RewriteRule \.(jpg|jpeg|png|gif)$ – [NC,F,L]

You’ll notice I included my feed (from FeedBurner), you’ll need to replace it with your feed’s name, otherwise your images won’t appear correctly there.

9. Add an expires header to static resources

An Expires header is a way to specify a time far enough in the future so that the clients (browsers) don’t have to re-fetch any static content (such as css file, javascript, images etc).

This way can cut your load time significantly for your regular users.

You need to copy and paste the following code in your root .htaccess file:

ExpiresActive On
ExpiresByType image/gif A2592000
ExpiresByType image/png A2592000
ExpiresByType image/jpg A2592000
ExpiresByType image/jpeg A2592000

The above numbers are set for a month (in seconds), you can change them as you wish.

10. Adjust Gravatar images

You’ll notice on this site that the default Gravatar image is set to… well, nothing.

This is not an aesthetic choice, I did it because it improves page loads by simply having nothing where there would normally be a goofy looking Gravatar logo or some other nonsense.

Some blogs go as far to disable them throughout the site, and for everyone.

You can do either, just know that it will at least benefit your site speed if you set the default image (found in “Discussion”, under the settings tab in the WordPress dashboard) to a blank space rather than a default image.

11. Add LazyLoad to your images

LazyLoad is the process of having only only the images above the fold load (i.e. only the images visible in the visitor’s browser window), then, when reader scrolls down, the other images begin to load, just before they come into view.

This will not only speed you page loads, it can also save bandwidth by loading less data for users who don’t scroll all the way down on your pages.

To do this automatically, install the jQuery Image Lazy Load plugin.

12. Control the amount of post revisions stored

I saved this post to draft about 8 times.

WordPress, left to its own devices, would store every single one of these drafts, indefinitely.

Now, when this post is done and published, why would I need all of those drafts stored?

That’s why I use the Revision Control plugin to make sure I keep post revisions to a minimum, set it to 2 or 3 so you have something to fall back on in case you make a mistake, but not too high that you clutter your backend with unnecessary amounts of drafted posts.

13. Turn off pingbacks and trackbacks

By default, WordPress interacts with other blogs that are equipped with pingbacks and trackbacks.

Every time another blog mentions you, it notifies your site, which in turn updates data on the post. Turning this off will not destroy the backlinks to your site, just the setting that generates a lot of work for your site.

For more detail, read this explanation of WordPress Pingbacks, Trackbacks and Linkbacks.

14. Replace PHP with static HTML, when necessary

This one is a little bit advanced, but can drastically cut down your load time if you are desperate to include page load speeds, so I included it.

I’d be doing this great post injustice if I didn’t link to it for this topic, as it taught me how to easily do this myself, in a few minutes.

So go there and check it out, it wrote it out in plainer terms than I ever could!

15. Use CloudFlare

This is similar to the section above on using CDN’s, but I’ve become so fond of CloudFlare since I discussed it in my best web analytics post that I’ve decided to include it separately here.

To put it bluntly, CloudFlare, along with the W3 Total Cache plugin discussed above, are a really potent combination (they integrate with each other) that will greatly improve not only the speed, but the security of your site.

Both are free!