30
@cwpnolen @emagineusa @WordPressRI #RIWP WordPress RI Meetup Evaluating Plugins How to decide if a plugin is right for your site

How to Evaluate WordPress Plugins Before Activating

Embed Size (px)

Citation preview

Page 1: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

WordPress RI Meetup

Evaluating PluginsHow to decide if a plugin is right for your site

Page 2: How to Evaluate WordPress Plugins Before Activating

Who Am I?Christian Nolen

Technical Director for emagine WordPress Developer

@cwpnolen

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 3: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Big Thank You to WordPress RI Meetup

Page 4: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Why?

Page 5: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

WordPress plugins are bits of software that can be uploaded to extend and expand the functionality

of your WordPress site.

iThemes

Page 6: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 7: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

22% of Hacked Sites are from poorly coded plugins

Page 8: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

• Decreased Performance • Broken Layout • White Screen of Death (WSOD) • Cross-Site Scripting (XSS) • SQL Injection • Arbitrary File Download • Broken Authentication • Denial of Service (DoS)

Potential Problems

Page 9: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Plugins aren’t bad some are just coded that way

Jessica Rabbit

Page 10: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

JetPack Yoast SEO

NinjaForms EWWW Image Optimizer

WP Mobile Detector

Page 11: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Why?

Page 12: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Non-Developer Stepsfor evaluating plugins

Page 13: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

1 Track Pros & Cons

Page 14: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

2What’s the Rating?

Page 15: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 16: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

3 Is it Maintained?

Page 17: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 18: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

4 Is there Support?

Page 19: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 20: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

5 Check for Vulnerabilities

Page 21: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

https://wpvulndb.com

WPScan Vulnerability Database

Page 22: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 23: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Page 24: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

6 Test Plugin on a Staging Site

Page 25: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

7 Benchmark Performance

Page 26: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

• Keep your plugins (themes and core) up-to-date

• Audit your plugins on a monthly basis.

• Subscribe to wpvulndb.com & other like services

• Get rid of un-used plugins • Backup your site nightly

Moving Forward

Page 27: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Resources• WPScan Vulnerability Database - https://wpvulndb.com/ • Plugins A-Z Podcast - http://wppluginsatoz.com/ • Importance of Updating - https://sucuri.net/website-

security/website-hacked-report • How WP Sites Get Hacked - http://torquemag.io/2016/03/

wordpress-sites-hacked/

Page 28: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Resources: Part Deux• Compare Plugins - https://managewp.org/plugins/compare • Site Speed - https://gtmetrix.com/ • Site Speed - http://www.webpagetest.org/ • Security Scanner - https://sitecheck.sucuri.net/ • Wordfence Email List - https://www.wordfence.com/

Page 29: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

Questions?

Page 30: How to Evaluate WordPress Plugins Before Activating

@cwpnolen @emagineusa@WordPressRI #RIWP

WordPress RI Meetup

Thank You