The Melapress Show

The Melapress Show

di Robert Abela
Behind the WordPress.org Plugin Review Process | Francisco Torres (WordPress Plugins Team)
Most WordPress users never think twice about the plugins repository: search, install, done. But behind that simple flow sits a review pipeline that handles roughly 800 new submissions a week, run by fewer than 10 active volunteers, with help from automated tools and AI. Francisco walks through how that process actually works, why plugin submissions have surged since AI coding tools took off, and where the system still can't fully protect against bad actors, including a real supply-chain attack the team dealt with after a popular plugin changed hands. Key topics include: How the review pipeline works, from the Plugin Check tool to AI-assisted first review to human reviewers Why the repository grew from 60,000 to 70,000+ plugins in under two years How AI model releases correlate directly with spikes in new plugin submissions How plugin ownership is verified and the limits of that system, illustrated by a real backdoor incident The "adopt me" tag and no-index system for abandoned or outdated plugins Why plugins get closed: guideline violations, sock puppeting, GPL issues, and security reports When the team closes a plugin immediately versus issuing a warning, and when they push a fix directly 🎙Guest: Francisco Torres, Representative, WordPress Plugins Team 🎙️Host: Robert Abela, Melapress
Recurring Revenue Playbook: Selling and Scaling WordPress Maintenance Plans | Josh Hall
In Episode 57 of the Melapress Show, Josh Hall, founder of Web Designer Pro, joins Robert Abela to discuss how to turn one-off WordPress projects into recurring maintenance revenue. Selling a maintenance plan is one of the trickiest parts of running a web design business: sell too early, and you seem pushy; wait too long, and the client walks. Josh shares the exact framework he used to grow his own agency and now teaches through his community, Web Designer Pro. Key topics include: The build-support-grow framework for introducing a maintenance plan at the right stage of a project What to include in a maintenance plan: hosting, updates, basic security, and monthly support hours Why bundling hosting with maintenance protects both the agency and the client, and how to handle clients who already have hosting elsewhere How to manage client admin access, from full access to limited roles, plus basic client training resources Setting plugin policies and liability clauses to protect the agency from unvetted client-installed plugins When and how to start delegating maintenance work as the client list grows, and how Josh's team is experimenting with AI without disrupting live client work 🎙Guest: Josh Hall, Founder of Web Designer Pro 🎙️Host: Robert Abela, Melapress
From Inquiry Form to Signed Client: An Agency's Real Qualification Process | Kyle Van Deusen
Do you quote a price after one 30-minute call? Kyle Van Deusen, owner of OGAL Web Design and founder of The Admin Bar community, stopped doing that years ago. Instead, a structured inquiry form, a no-cost "vibes check" call, and a paid discovery workshop come before any number gets attached to a project: a process that's fixed his scope creep problem for good. Key topics include: Designing a lead inquiry form with conditional logic so prospects only answer what's relevant to their project The single question on Kyle's intake form that tells him exactly how sold a prospect already is Running an unpaid 30-minute discovery call to gauge fit before ever discussing price Why Kyle charges for a website workshop before pricing any real project, and what that session covers How detailed discovery prevents scope creep and protects both agency and client from wasted money Structuring website management retainers, including editor vs. admin access, so clients never get accidentally locked out or accidentally break their own site 🎙 Guest: Kyle Van Deusen, Owner of OGAL Web Design & Founder of The Admin Bar 🎙️Host: Robert Abela, Melapress
Accessibility, Revenue, and the Mistakes Most Agencies Keep Making | Anne-Mieke Bovelett
Most organizations only consider accessibility when faced with a legal deadline or a complaint. Anne-Mieke Bovelett's approach begins much earlier, at the stage of product decisions, design systems, and CMS workflows that ensure a site is accessible for everyone before any code is written. With 27 years of experience in web infrastructure across retail, academic, agency, and enterprise clients in the Netherlands, Germany, and beyond, she knows exactly where agencies often go wrong with accessibility, and the consequences of these mistakes. In this conversation, Anne and Robert unpack the gap between technical compliance and real-world usability, explain why accessibility, SEO, usability, and conversion optimization are increasingly the same discipline, and discuss how AI search and agents are raising the stakes for clear semantic structure. Key topics include: Why "WCAG compliant" doesn't guarantee a usable website The accessibility mistakes that show up on WordPress sites regardless of who built them How to reframe accessibility as an investment instead of a project cost Where accessibility debt gets introduced during discovery, design, and development What metrics actually demonstrate accessibility ROI to a client How AI-driven search and agents change the value of accessible, well-structured content 🎙️Guest: Anne-Mieke Bovelett, Accessibility Strategist 🎙️Host: Robert Abela, Melapress
Regression Testing, Visual Testing & QA: What WordPress Pros Need? | Mike Miler (WebChange Detector)
Agencies applying updates across dozens of client sites face a consistent challenge: the issues that matter most, such as broken forms, failed checkouts, and layout regressions, rarely surface on the homepage. Without a structured testing process, these issues surface only when a client notices. Mike Miler, Founder of WebChange Detector, works with agencies on exactly this problem and brings a grounded, tool-informed perspective on where testing effort actually pays off. Key topics include: The practical difference between testing, monitoring, and QA, and why each serves a different purpose in a maintenance workflow How regression testing and visual testing work, and the distinct failure types each one is designed to catch Which change types carry the highest risk: plugin and theme updates, design changes, third-party integrations, or configuration changes How to structure a QA checklist that's consistent and repeatable across multiple team members What to automate when managing websites at scale, and what still requires a human review step Practical uses of AI in generating test coverage and flagging anomalies 🎙 Guest: Mike Miler, Founder at WebChange Detector 🎙️Host: Robert Abela, Melapress
WordPress Playground Deep Dive: Making WordPress Easier to Try and Learn | Adam Zielinski (Automattic)
Getting started with WordPress, whether as a learner, a contributor, or an agency evaluating plugins for a client, has always required more setup than it should. WordPress Playground was built to address that friction directly, making it possible to run a full WordPress environment in the browser, instantly, with no installation required. In this live episode, Adam Zieliński shares how the project has evolved, the adoption patterns that surprised the team, and the common misconceptions that still follow Playground around. Key topics include: The original problem WordPress Playground was created to solve, and why instant access matters How agencies are using Playground for plugin and theme evaluation, product demos, and client onboarding Interactive learning approaches versus traditional tutorials, and how Playground is reshaping WordPress education Reducing setup friction for contributors and making it easier to reproduce, test, and share issues Where AI and experimentation intersect with Playground, and what unexpected use cases have emerged Adam's vision for where Playground fits in the next generation of WordPress workflows 🎙Guest: Adam Zieliński, WordPress Core Committer & Architect of WordPress Playground 🎙️Host: Robert Abela, Melapress
WordPress Plugin Supply Chain Attacks: Hunting for Backdoors with AI | Austin Ginder (Anchor Host, WP Beacon)
Supply chain attacks against WordPress plugins are difficult to spot because they often hide behind legitimate update processes that users trust every day. In this episode, Austin Ginder, Founder of Anchor Host and WPBeacon, shares how investigating compromised sites across a large managed WordPress environment led him to uncover multiple examples of plugin supply chain abuse. He explains the techniques involved, how AI accelerated the investigation process, and what the WordPress ecosystem can do to improve software integrity. Key topics discussed: • How plugin supply chain attacks operate through trusted update channels • The attack patterns Austin investigated, including expired domain takeovers, redirected update infrastructure, and version number manipulation • How Claude Code accelerated timeline reconstruction and forensic investigation • WPBeacon and its role in identifying indicators of supply chain compromise • WPRegistry and the vision for a community-driven plugin integrity database • The challenges surrounding abandoned plugins and ecosystem governance • The growing impact of AI on both attackers and defenders 🎙Guest: Austin Ginder, Anchor Host & WP Beacon 🎙️Host: Robert Abela, Melapress
AI in WordPress Core: Connectors, Abilities & How to Stay Secure | Jonathan Bossenger (Automattic)
In Episode 51 of the Melapress Show, Jonathan Bossenger, Developer Advocate at Automattic, joins Robert Abela to break down how WordPress is being rebuilt from the ground up to work with AI and what that means for the people who build and manage WordPress sites. The conversation covers the four Core AI building blocks that shipped with WordPress 7, why the Abilities API could change how developers structure their plugins, and the real security considerations involved in connecting your site to an AI provider. Whether you're a seasoned plugin developer or just getting started, this episode gives you a clear picture of what's happening now and where things are heading. Key topics include: The four WordPress Core AI building blocks: Abilities API, AI Client, MCP Adapter, and Connectors How the user-controlled model means site owners decide how AI is used on their site Why connecting to AI providers makes API key security more critical than ever, and what to do about it How to get a feature request or idea into the hands of the right WordPress Core contributors What the Abilities API does, why it matters for plugin developers, and how to start registering abilities What the WordPress AI plugin is, how it mirrors the Gutenberg/performance plugin model, and where it's heading How AI is reshaping the developer role and why experienced developers blogging and sharing more matters now more than ever 🎙 Guest: Jonathan Bossenger, Developer Advocate at Automattic 🎙️ Host: Robert Abela, Melapress
Building Modern WordPress Products in the AI Era | Vova Feldman (Freemius)
In this 50th episode of the Melapress Show, Vova Feldman, Founder & CEO of Freemius, joins Robert Abela to explore how AI is transforming the way WordPress products are built, maintained, and supported. While AI is making development faster than ever, many plugin vendors are discovering that speed alone doesn't solve the harder problems: technical debt, support at scale, product quality, and the growing complexity of modern SaaS-connected WordPress products. This conversation goes beyond the hype, offering a grounded look at where the ecosystem is heading and which skills and processes still matter in an AI-assisted world. Key topics include: - How AI is accelerating WordPress plugin and product development, and where the risks are emerging - Why technical debt is a growing problem as building speed outpaces engineering discipline - The evolution from standalone plugins to modern, SaaS-connected WordPress products - How to maintain product quality and reliability as operational complexity increases - Scaling support effectively without sacrificing the user experience - What engineering skills and development practices remain essential in the AI era 🎙️ Guest: Vova Feldman, Founder & CEO at Freemius 🎙️ Host: Robert Abela, Melapress
REGEXSS Demo: How Hackers Exploit Regular Expressions in WordPress | Matthew Rollings (Stealthcopter)
In Episode 49 of the Melapress Show, Matthew Rollings, application security professional and bug bounty hunter, joins Robert Abela to break down RegexXSS: a vulnerability class hiding in the regex code of WordPress plugins. Mat explains how post-sanitization regex manipulation can reintroduce cross-site scripting even after WordPress has done its job, and demonstrates how an attacker can leverage it to take over a full admin account. Many developers are unaware that using regex to parse or modify HTML, even after WordPress's built-in KSES sanitization, can introduce fresh XSS vectors. With over 70,000 WordPress plugins in existence, and regex used heavily throughout PHP development, this vulnerability class is both widespread and chronically under-reported. Mat has earned £20–30k in bug bounties from this single class alone. Key topics include: The definition of RegexXSS and why it's distinct from conventional cross-site scripting How WordPress sanitizes input by default and exactly where that protection ends Why regex is fundamentally context-unaware and therefore unsafe for HTML manipulation A step-by-step demo of abusing a regex deletion to smuggle a JavaScript payload How XSS can be escalated to silent admin account creation in WordPress 🎙 Guest: Matthew Rollings, Application Security Professional 🎙️ Host: Robert Abela, Melapress
1 di 6