Sitelet https://github.com/lightspeedwp/.github/issues/1396
Skip to content

Plugin advisories: native replacements, Gravity Forms usage and hosting-stack guidance #1396

Description

@eleshar

Scope

Create a single versioned document holding the plugin advisories, so the guidance lives in one reviewable place alongside the approved plugin register.

Section 1 — Replaced natively in the starter theme/plugin

For each of these, state the plugin, the native replacement, and the caveat:

Plugin Native replacement
Safe SVG upload_mimes gated on a capability + enshrined/svg-sanitize on upload
WP Mail SMTP, Change Mail Sender phpmailer_init from constants + sender fields in Settings → General
Cachebuster filemtime() asset versioning helper
Disable Emails pre_wp_mail short-circuit driven by wp_get_environment_type()
View Transitions native CSS @view-transition
Carousel Slider Block CSS scroll-snap with core blocks
GTM4WP, Google Site Kit container snippet and dataLayer output from the enhancement plugin
WPFront Scroll Top CSS plus a few lines of JS in the theme
Disable Comments RB core discussion settings
User Menus, Visibility Logic for Elementor block theme templates and template parts
Social Sharing Block pattern with plain share URLs, no JS
JWT Authentication for WP-API core Application Passwords
Yoast Duplicate Post row action plus wp_insert_post clone

Section 2 — Gravity Forms usage advisory

  • Gravity Forms is the approved platform for enquiry, application, quote and upload forms.
  • It must not be used for elements rendered site-wide, newsletter sign-ups, or pop-ups. Its front-end payload is disproportionate for those cases and it degrades Core Web Vitals.
  • Document the required alternative: a newsletter sign-up is a plain form posting to a REST route that calls the provider API; a pop-up is <dialog> with minimal JS. Include a reference implementation for each so the advisory is actionable rather than only a prohibition.

Section 3 — Do not replace natively

State explicitly, with reasons, that these stay as plugins: Gravity Forms itself, Wordfence, User Switching, Yoast SEO, all payment gateways, WooCommerce Subscriptions, FacetWP, SearchWP, Sequential Order Numbers.

Section 4 — Hosting-stack advisories

  • WP Rocket: the LightSpeed fleet already runs nginx FastCGI page caching and Cloudflare edge caching. A third page-cache layer is redundant and a stale-content risk. Approve for asset optimisation only, or not at all, on LightSpeed hosting.
  • Accessibility Checker: run accessibility checks in CI (axe or pa11y in a GitHub Action) rather than as a production plugin.
  • Redirection: prefer server-level redirects for migrations and bulk URL changes; use the plugin only where editors need to manage redirects themselves.
  • Analytics: one tool owns each event. No duplicate purchase, checkout or form events across Site Kit, GTM, WooCommerce Google Analytics Pro and the Gravity Forms add-on.

Acceptance criteria

  • Document is committed to this repo and linked from the approved plugin register.
  • Every advisory names the replacement or the alternative, not only the restriction.
  • Each native replacement links to its implementing reference: a tracking issue or pull request in block-plugin-scaffold / block-theme-scaffold where the replacement is generator-specific code, or the official WordPress core documentation where the replacement is a WordPress core feature.
  • Sections 2 and 4 each carry a stated reason, so the guidance can be reviewed rather than taken on trust.
  • Document has a review owner and a last-reviewed date.

Definition of Ready (DoR)

  • Clear problem statement and expected outcome
  • Acceptance criteria defined
  • Related issues/dependencies identified
  • Required resources/approvals listed

Definition of Done (DoD)

  • All acceptance criteria met
  • Changes tested and validated
  • Documentation updated
  • Changes merged and deployed
  • Stakeholders notified

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Fields

Priority

None yet

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions