WordPress performance: fixing the fetchpriority logic
Core was tagging hidden Gutenberg images as high priority and hurting LCP. Ticket #64823 fixes that, and Performance Lab is dropping Web Worker Offloading after 6,000 updates with no feedback.
Core was tagging hidden Gutenberg images as high priority and hurting LCP. Ticket #64823 fixes that, and Performance Lab is dropping Web Worker Offloading after 6,000 updates with no feedback.
Magic numbers like z-index: 99999 are guesses. How I set up z-index tokens in CSS variables, pair a modal with its backdrop using calc(), and use isolation to keep a component’s layering inside the component.
Almost every WordPress vulnerability comes from a plugin or theme, not from core. Where the risk actually sits, the hardening I put on sites I manage, and the maintenance habits that keep them clean.
CVE-2026-3589 is a CSRF flaw in the WooCommerce Store API, affecting versions 5.4 to 10.5.2, that can be used to create admin accounts through batch requests. How the flaw works, and how to check your own version with WP-CLI or a small PHP snippet.
WooCommerce 10.5.3 patches a path validation bug in the Store API batch endpoint that let attackers skip nonce checks and gain admin access via CSRF. Don’t roll back to 10.5.2; update now and test your checkout.
Ahmad Wael breaks down why overusing FILTER() in DAX forces work into Power BI’s slow, single-threaded Formula Engine, and how a simple predicate lets the Storage Engine (VertiPaq) handle it instead.
Ahmad Wael explains CVE-2026-2441, a Use-After-Free bug in Chrome’s Blink CSS engine triggered through @font-feature-values. It’s not literal code execution via CSS, but it’s a real reason to update your browser now.
AI agents optimize for code that runs, not code that is safe. Two failures I keep finding in agent-written WordPress code, hardcoded API keys and REST routes with no permission callback, plus the review habits that catch them.
Writing the README and wiring up CI is the part everyone puts off. OSA is a multi-agent tool that reads the repository, drafts the docs and docstrings, and generates the workflow files. Here is how it works and how to run it.
WooCommerce 10.5.2 reverts the change that left the Add to Cart button disabled on variable products when a theme or plugin altered how the variation scripts load. What went wrong, and the WP-CLI steps to update without stale variation data.