• 0
Serious flaw fixed in widely used WordPress plug-in

Serious Flaw Fixed In All in One SEO Pack WordPress Plugin..!

Tags :

Category : Blog

There is a serious stored cross site scripting (XSS) vulnerability in All in One SEO Pack Plugin versions 2.3.6.1 and older. This plugin is installed on over 1 million active websites and is extremely popular and widely used.

The vulnerability is in the plug-in’s Bot Blocker functionality and can be exploited remotely by sending HTTP requests with specifically crafted headers to the website.

The vulnerability allows an attacker to send a malicious HTTP User-Agent or Referrer header to the site containing an XSS payload. If the administrator then visits their admin panel and views the “Bad Bot Blocker” settings page in this plugin, the attacker can take full control of their site.

The Bot Blocker feature is designed to detect and block spam bots based on their user agent and referer header values, according to security researcher David Vaartjes, who found and reported the issue.

This vulnerability is only exploitable on sites that have the “Track Blocked Bots” setting enabled. This setting is not enabled by default. There is no definitive data to indicate how many users of the plugin have enabled this feature. However, this plugin is extremely popular:

  1. All in One SEO Pack has been downloaded over 28 million times (this includes upgrades)
  2. It has been around for over 9 years
  3. It is one of the most downloaded WordPress plugins. But Akismet, Yoast SEO and Contact Form 7 have more downloads.

How to Prevent  :

If you’re running a WordPress website and you have the hugely popular  plug-in installed, it’s a good idea to update All in One SEO Pack  version 2.3.7  as soon as possible. The latest version released Friday fixes a flaw that could be used to hijack the site’s admin account.

Bezoar Software  customers are already protected against exploitation of this vulnerability. We are offering a simple and hands off  WordPress maintenance service . We not only keep your WordPress website up to date, but we become a virtual team that handles many issues that may come up on your behalf.

Feel free to reach out to Bezoar Software via info@bezoarsoftware.com or 844-4-BEZOAR (844-423-9627) for details on the web design and development services that we offer.


More…

This vulnerability was discovered by David Vaartjes and you can find the full technical details of the vulnerability on his site.

A proof of concept has been published on exploit-db, which means this attack is already spreading.

This story has received coverage in the past few days from The RegisterWP Tavern,Softpedia.com and is on the Various Tech News Service which includes CIO.com ,PCWorld and ComputerWorld.



  • 0
wordpress-cheat-sheet-2016

WordPress Superb Cheat Sheet for Designers and Developers 2016

Category : Blog

Since WordPress is premiere CMS and blogging platform that’s not only incredibly versatile, but also amazingly easy to learn and use. Majority of Business professionals prefers WordPress to develop their business websites. Moreover, since it’s open source and completely free to use, there is a common misconception that WordPress is meant for amateurs, not for serious business purposes.

WordPress UI: The front-end and back-end.

Front-end includes your content (posts, pages, media, and comments), your theme (how everything looks and feels), menus (typically used for navigating around your site), and widgets (depending on whether your theme supports widgets, of course).

Back-end is the admin area is where most work gets done in WordPress; it’s where you author new content, manage users, configure your site’s options, and perform regular maintenance tasks.

But what you see on the surface when you set up and launch WordPress UI is just a small fraction of what goes on behind the scenes. That means, WordPress runs on two somewhat complicated web technologies known as PHP and MySQL. Other technologies that play a part include JavaScript, it’s close cousin jQuery, CSS and HTML. WordPress themes (and even plugins) are mainly written in PHP, and rely on MySQL databases to run.

Now, for amateurs, there sure is a lot to remember when working with WordPress files. From the names of basic template files to functions and how the WordPress Loop works, themes and plugins to work, use a set of standardised code and it’s next to impossible to remember every PHP tag or even how to define a new theme. So to help you out, present you handy and superb cheat sheet. This is definitely one to bookmark and save for future reference!


Theme Files and Structure :

WordPress Cheat Sheet-The Anatomy of Theme

These are the basic files that every theme should include:
  • style.css – This is your theme’s stylesheet file.
  • index.php – This is the main body template for your theme. Its job is to bring together all the information in the other theme files using template tags.
  • header.php – This file contains the header information that appears with the <head> section of your site, stuff like metadata and the link to your stylesheet.
  • sidebar.php – Everything in you sidebar goes in this file, like widgets, categories, additional menus, search form, etc.
  • footer.php – This file contains your footer information, such as copyright details, widgets, and social icons.
  • single.php – This file displays just one post.
  • page.php – When you create a page on your site, this is the template responsible.
  • comments.php – This file is responsible for displaying comments.
  • 404.php – When visitors try to visit a page on your site that doesn’t exist, this file will general an error page.
  • functions.php – This file is where you can place special functions. We always recommend creating a child theme rather than edit this file directly.
  • archive.php – Display an archive with this file so visitors to your site can go way back when and read your Hello World! post.
  • search.php – Help your visitors search your site with this page.
  • searchform.php – Display a search form for your visitors with this template file.

Defining a New Theme Style Sheet:

Why is style.css file important? Firstly, it provides details about your theme that are displayed in the Appearance > Themes section. This information goes into the style-sheet header, which helps in identifying the theme during selection in the admin area.

The following is an example of the first few lines of the style sheet for the default Twenty Sixteen theme:

/*

Theme Name: Twenty Sixteen

Theme URI: https://wordpress.org/themes/twentysixteen/

Author: the WordPress team

Author URI: https://wordpress.org/

Description: Twenty Sixteen is a modernized take on an ever-popular WordPress layout — the horizontal masthead with an optional right sidebar that works perfectly for blogs and websites. It has custom color options with beautiful default color schemes, a harmonious fluid grid using a mobile-first approach, and impeccable polish in every detail. Twenty Sixteen will make your WordPress look beautiful everywhere.

Version: 1.2

License: GNU General Public License v2 or later

License URI: http://www.gnu.org/licenses/gpl-2.0.html

Tags: black, blue, gray, red, white, yellow, dark, light, one-column, two-columns, right-sidebar, fixed-layout, responsive-layout, accessibility-ready, custom-background, custom-colors, custom-header, custom-menu, editor-style, featured-images, flexible-header, microformats, post-formats, rtl-language-support, sticky-post, threaded-comments, translation-ready

Text Domain: twentysixteen




This theme, like WordPress, is licensed under the GPL.

Use it to make something cool, have fun, and share what you've learned with others.

*/

Template Include Tags:

Template include are simply PHP codes used within one template file (for example index.php) to include (or call) the HTML and PHP found in another template file (for example header.php). While PHP has its own built-in include() statement to do this, these WordPress-specific tags make coding easier:

  • <?php get_header(); ?> – Use this in index.php to call (or include) the header.php file. It will fetch header.php and display its content in index.php – that’s what including a file all is about.
  • <?php get_sidebar(); ?> – Includes sidebar.php
  • <?php get_footer(); ?> – Includes the footer.php template file
  • <?php comments_template(); ?> – Includes your comments

Template Bloginfo Tags:

They play one role, which is to fetch information about your WordPress site from the database. This is mainly the information you feed to your WordPress site in your admin area via the User Profile and Settings -> General. These are functions you’ll find in your theme’s header.php file, though you’ll also find them in other theme files:

  • <?php bloginfo(‘name’); ?> – The title of your site, or blog name
  • <?php bloginfo(‘url’); ?> – Your site’s URL
  • <?php bloginfo(‘stylesheet_url’); ?> – Link to your themes’s stylesheet file
  • <?php bloginfo(‘template_url’); ?> – Location of your site’s theme file
  • <?php bloginfo(‘description’); ?> – Displays the tagline of your blog as set in Settings > General.
  • <?php bloginfo(‘atom_url’); ?> – Link to your site’s atom URL
  • <?php bloginfo(‘rss2_url’); ?> – RSS feed URL for your site
  • <?php bloginfo(‘pingback_url’); ?> – Pingback URL for your site
  • <?php bloginfo(‘version’); ?> – WordPress version number
  • <?php bloginfo(‘html_type’); ?> – The HTML version your site is using
  • <?php site_url(); ?> – The root URL for your site
  • <?php get_stylesheet_directory(); ?> – Location of your stylesheet folder
  • <?php wp_title(); ?> – Title of a specific page

Template Tags:

These tags can be used across all of your template files, such as index.php or page.php, making it easy to display specific information anywhere you want on your site:

  • <?php the_content(); ?> – Displays the content of a post
  • <?php the_excerpt(); ?> – Displays the excerpt used in posts
  • <?php the_title(); ?> – Title of the specific post
  • <?php the_permalink() ?> – Link of a specific post
  • <?php the_category(‘, ‘) ?> – Category of a specific post
  • <?php the_author(); ?> – Author of a specific post
  • <?php the_ID(); ?> – ID of a specific post
  • <?php edit_post_link(); ?> – Edit link for a post
  • <?php next_post_link(‘ %link ‘) ?> – URL of the next page
  • <?php previous_post_link(‘%link’) ?> – URL of the previous page
  • <?php get_links_list(); ?> – Lists all links in blogroll
  • <?php wp_list_pages(); ?> – Lists all pages
  • <?php wp_get_archives() ?> – List archive for the site
  • <?php wp_list_cats(); ?> – Lists all categories
  • <?php get_calendar(); ?> – Displays the built-in calendar
  • <?php wp_register(); ?> – Displays register link
  • <?php wp_loginout(); ?> – Displays login/logout link only to registered users

The Loop:

The loop, or WordPress loop or simply loop, is PHP code structure that displays WordPress posts. The loop is used in WordPress themes to display a list of posts in a web page.

There are several Template tags that work only inside the WordPress loop and can be used to format, arrange, and publish post data. The WordPress loop is arguably one of the most important aspects of the WordPress code and at the core of most queries in one way or another.

The following code snippet wherever in your WordPress template files, and it’ll list all posts you’ve ever created:

<?php

if ( have_posts() ) {

        while ( have_posts() ) {

               the_post();

               //

               // Post Content here

               //

        } // end while

} // end if

?>

Final Thoughts

This cheat sheet is just a quick guide that will help you get started as you learn WordPress theme development. Using the tags, functions and snippets we’ve shared here, you can easily go through slandered theme development, and enhance it without breaking a sweat .But of-course, you need to keep learning WordPress theme development and latest development trends, and for that we recommend the WordPress Codex, tuts+, Threehouse, ManageWP.org, and ThemeShaper among other great resources.

Other than that, Bezoar Software caters diverse WORDPRESS DEVELOPMENT SERVICES or if you wish to migrate to WordPress from any CMS , we will make it smooth and hassle-free with our unmatched services. To know more visit our website http://bezoarsoftware.com or write us info@bezoarsoftware.com .


  • -
Why Migrate to WordPress- 5 solid facts you must know

Why Migrate to WordPress- 5 solid facts you must know..!

Web design and development is constantly evolving and this is especially true when it comes to WordPress. We are WordPress developers, so of-course we prefer and recommend using WordPress to build websites.-

As per latest trends 86% clients prefers WordPress platform for build website. In case you’re wondering what the other 10% are, those are a mix of custom content management systems, Drupal or Joomla or Magento websites – all of which we only build when a client specifically requires us to do so.

Below are some solid facts Reasons to Switch to WordPress.

1. Word-Class Community for Everyone.

WordPress powers 25% of all websites on the web: That makes for over 4 billion websites created and run by countless developers and admins. Originally created as a blogging platform, WordPress has since grown into one of the most popular website / blog platforms on the Internet. It is estimated that over 20% of all new websites are built on WordPress. On top of that, of the top 100 blogs on the web, just about half of them are built on WordPress. These are just a few of the many impressive stats that WordPress can boast about its adoption and usage.

You accept your trend-setters, out-of-the-box-thinkers, non-coding but acutely accomplished WordPress users, artistic web and clear designers, and just about all levels of skill-sets on WordPress Forums for Support and Core development.


2.Easy Management

WordPress is well-loved by over a quarter of the netizens for its super friendly admin interface. Of all our clients who opted for HTML to WordPress conversion service, every single one of them took to the platform like a duck to water.

WordPress has consistently had user-friendliness at its core: Every content-related task, from announcement to editing, commenting, categorising, marketing, advance apparatus and all-embracing administration of the website is done through an simple to use admin area. Writing and formatting your posts is as simple as application a rich-text editor like Microsoft Word.

With every update, WordPress makes it a point to enhance the admin experience. Currently, WordPress dashboard is clean, quick to load, and acknowledging to boot.


3.Ease of Customization

This one is a win-win for coding and non-coding communities.

For those who can accomplish abracadabra appears with frequently used programming languages, WordPress provides the mechanism for faster, smoother development of amazing websites. The APIs, templates hierarchy, anatomy and metadata, the built-in PHP debugging constants, the coding standards (maintained by analysis committees) and so abundant added advice accomplish a developer’s job easier.

It’s also easy to manage and customize WordPress without knowing a single thing about code, thanks to hundreds of thousands of free and premium themes and plugins. In two simple accomplish (install and activate), you can change the blueprint and architecture or add any affection and functionality you wish to your WordPress website. It actually takes no best than a few minutes, which is nothing compared to hours of work you have to devote trying to make even the smallest change in an HTML website.


4.Search Engine Optimization and WordPress

Any website can rank top on SERP’s with craftily accounting content, quick page load time, and abundant user experience. On HTML you would accept to await on cipher to do that. WordPress practically simple to use and absolutely able accoutrements for online success.

Websites built on WordPress have an offbeat  advantage in SEO, even without additional plugins or tools. Configure permalinks in WordPress , and get cocky independent taxonomies to accomplish analysis easy.Default wp-templates are coded to make your content easy to crawl on search bots and visible easily . Professional developers can plan with your  brand to customize WordPress with better navigation that only augments the platform’s SEO-friendliness.

Moreover , plugins that help SEO like WordPress SEO by Yoast or All-in-one SEO pack, improve performance (page speed) with caching plugins, and enhance user-experience scores with a responsive theme: you are all set for success without hassle.


5.Flexibility and Scalability

WordPress currently runs more than 66 million websites. Some of those sites include CNN, TechCrunch, Forbes, and many other popular sites that you probably use or see every single day!

The CMS is used by a millions of websites for all sorts of purposes. Despite starting out as a blogging platform, it is now used widely to create interactive online experiences for eCommerce stores, portfolios, communities (social), education, news, and more verticals.

Moreover, WordPress is only platform fits as beautifully around your requirements and constraints while not compromising service or quality. Even if you don’t have a skilled coder, you own to create, setup, customize, and maintain your WordPress website


Key Takeaways..!

Just the one: With the same budget, skill, and time you can accomplish so much more on WordPress than on an HTML website.

If you already have a website and considering switching it from HTML to WordPress: research proper conversion and migration process. If you don’t have professionals and latest equipment, hire a team you can trust to convert your website.

Bezoar Software caters diverse WORDPRESS DEVELOPMENT SERVICES. If you wish to migrate to WordPress from any CMS, we will make it smooth and hassle-free with our unmatched services. To know more visit our website http://bezoarsoftware.com or write us info@bezoarsoftware.com .


  • -

Which Social Community is excellent for your on-line business?

Category : Blog

In this era there are so many businesses and so there are many advertising mediums for businesses to promote social media and networking making use of social community. Nonetheless most business proprietor asks themselves which social network they should use for their business. Using well-known advertising mediums would be the great choice. Facebook, Twitter and LinkedIn are most famous and well known throughout the world and tend to have easier access when it comes to clients.


Social Media by Small Business

Use of Social Media in Percentage by Small Businessess

Why You Must Use Facebook to Promote Your Business ?


Facebook is leading among all the social websites with 82% of small businesses registered; it is followed by YouTube, Twitter and LinkedIn with 73%, 47% and 47% respectively. (Source: Mediabistro).

Facebook has many different features that allow you to promote your marketing material. Here are a few:


  • Creating a Facebook ad (and there are analytics included!)
  • Hosting a Facebook contest
  • Promoted Facebook posts

Facebook has made it easy for businesses to create their own business profiles and company pages in order to connect with the audience. Using page you can promote your company news and services via post and check for notifications such as how many people like and share your posts as well as check what people are saying on your own page.Facebook also allows you to write a longer or more complete post regarding what you want to promote like new product description or service. It gives you the opportunity to give a proper description with as much detail as possible. There is a limit of course, but you would be able to say all you need in one post.


49% of Users Prefer to Interact with Brands via Twitter..!!

Like Facebook, you can also use Twitter as it is also most popular social network. Twitter doesn’t allow as many characters as Facebook does as it gives the audience limited sentence to read. So it is great for quick glances of interesting news. With Twitter you can add links which takes readers to websites, articles or videos. This is similar to Facebook, but it is ideal for people who don’t feel like reading too much. Re-tweeting gives your follower’s followers an insight into what you do and what you post. It makes you more known. A wider variety of people will see what you have to offer instead of just the family and friends of followers. You may be able to reach more people with those followers. Furthermore, hash-tagged words can be entered in the search bar for the purpose of finding trending news.

With Twitter, you are limited to 140 characters so you want your content to be interesting and eye-grabbing. One way you can achieve call-to-action by technically using more than 140 characters is by using a Twitter Card. A Twitter Card is a snippet for tweets that are ideal for engagement and overall appeal. Shopify offers a few creative ways on how to use Twitter Cards:

  1. Promote Contests
  2. Introduce New Products
  3. Share resources
  4. Piggyback on current events
  5. Share videos
  6. Generate leads

LinkedIn For Business ?

Another social network to consider is LinkedIn. Whether you want to connect with industry professionals, network, attract clients, establish thought leadership, or generate prospects and leads (or indeed, all of the above), LinkedIn should be an integral part of not just your social media marketing strategy, but also your overall inbound marketing strategy.

LinkedIn has about 280 million users of which 80% spend less than eight hours a week on the site, according to The Undercover Recruiter. A whopping 76.9% of users claimed LinkedIn helped them research people and companies. LinkedIn has many features that most forget about and here are the top 5:

  1. Groups
  2. People Searching
  3. People You May Know
  4. Who’s Viewed You
  5. Company Information

The social network marketing platform depends on the type of business and what their intentions are. If they want to have long promotional posts with adverts and images, then Facebook would be the best option. If the target market is interested in posts about snippets of news and technology trends, then Twitter is a good option to use. If the business only focuses on generating prospects and leads then LinkedIn would be the better option.

Bezoar Software, web design and Development Company in USA offering resilient web and mobile apps solutions, digital marketing solutions. Contact us now to achieve your on-line success.

Visit our website http://www.bezoarsoftware.com for more information on our services.

  • -
small business or start-up WordPress themes

7 Best Small Business or Start-up WordPress Themes -2016

Category : Blog

As more people surf the Internet to search for information, a user’s first impressions of a website can determine whether he or she forms a positive lookout for that organization. Especially in case of Small Business or Startups Website “first impression is VERY IMPORTANT”.

The perfect design and style that’s friendly to on-line readers, fresh and quality content and a clear description of who you are; these are main factors that makes your business reckonable on the web so all those millions of users out there know you exist.

In this article, we’re representing the list of best WordPress themes which can take care every aspect of a startup and small business. Whether it’s a Woo Commerce ready website, picture gallery site, blog or a virtual business, small business. So, here is our latest collection of the WordPress themes and templates.

Let’s enjoy the ride…

1. Rebloom

Rebloom- Responsive Vertical Menu Split Page Theme by themeforest is uniquely designed template for small business and startup with Sophisticated, creative layout concept, but still multi-purpose. Every page can use a different layout, unique navigation feature with off-canvas mobile navigation and obvious it is clean coded and responsive as well. One of the unique feature ‘chapters’ feature that can be used for software documentation purposes, also one can upload infinite portfolio and blog summary pages.

Click Here for a Live Demo. Click Here to Download.

Rebloom


2. Business Plus

Business plus – Corporate Business WordPress theme an interactive and modern business WordPress theme specially designed for Corporate, Agency, Creative, Personal, and small or large business websites. The features makes this theme best that it is Coded LESS CSS and responsive fluid layout and it has been built on Mobile First Approach. Compatible with woo-Commerce and Buddy press. Through Business plus WordPress multipurpose theme, one can create 100% W3C validated & SEO-friendly web pages that are capable of caching on Google & other major search engines.

Click Here for a Live Demo. Click Here to Download.
Business plus – Corporate Business WordPress Theme

3.KANA

KANA – Creative Agency WordPress Template one of the most beautiful themes. It is minimal & creative featured template which is suit for agency, portfolio & corporate. Eye catchy look, modern and unique design makes this template perfect for all kind of business. The theme is perfectly organized for the users so that one can easily change each section very smoothly without any knowledge of code weather it is text, images, colours everything that user need. All this makes it a great choice for people searching for quality small business WordPress themes for startup.

Click Here for a Live Demo. Click Here to Download.

KANA - Creative Agency WordPress Template


4. Arabella

Arabella – WordPress Portfolio Theme by themeforest. As the name suggests specially designed for showing your valuable portfolio with very organized and creative manner. This theme is perfect solution for Web Designers, Graphic Designers, Architecture, Photography and any kind of creative people. Features like superb eye-catching animations with the use of modern CSS3 and jQuery makes representation of your work/portfolio get praised by visitors comes to your website

Click Here for a Live Demo. Click Here to Download.

Arabella wordpress theme


5. Gemiz

Gemiz – Portfolio WordPress Theme it’s again template based on HTML 5, CSS3 and jQuery for your portfolio. The robust features like visual composer with drag and drop layout for easy to use. It is responsive design included light and dark versions theme options and also has 2 stylish home page sliders (LayerSlider, Sync slider) makes descent look for your website. For portfolio page themes includes fully responsive media grid plugin that allows you to control the layout of your item grid in the way that pleases you most. One can make creative portfolio website weather it Business or Agency.

Click Here for a Live Demo. Click Here to Download.

Gemiz WordPress Themes


6. Viano

Viano Portfolio WordPress Theme by themeforest has everything a startup might need: simplicity, a professional look, and a clean layout with well-organized content purposely for designers, creative individuals who want to showcase their works beautifully. One can use it for portfolio, personal and agency site. A theme built with amazing customizes options that are its plus point. Also for showcase your beautiful work simple and effective Viano provide Masonary and grid to list options. More features such as functional models, working contact form, pricing tables included to create awesome portfolio for your company or business.

Click Here for a Live Demo. Click Here to Download.

Viano WordPress Theme


7. Wizard

Wizard – Full-page Portfolio WordPress Theme; Perfect for creative portfolio websites, fashion websites, photography portfolios, small business websites or any creative business or agency! Theme packed with very powerful features includes powerful Visual Composer page builder plugin to create wonderful content, dark and light version for Panels, and also separate section for homepage to create various styles for front-page as per requirement. Fully customizable theme with Responsive Bootstrap 3 Grid system and awesome retina icons also makes this theme perfect for creative business.

Click Here for a Live Demo. Click Here to Download.

Wizard - Full-page Portfolio WordPress Theme