For as long as anyone in the WordPress community can remember, the minimum allowed version of php on which WordPress will run has been well behind modern php versions, thanks to WordPress’s commitment to backwards compatibility. As of version 5.2, (due out in April) the minimum allowed version will be raised to php version 5.6, from it’s current allowed version of 5.2. Eight-five percent of all sites running WordPress 5.0 are running on php 5.6 or above, and high-profile plugins have been experimenting with user notifications encouraging an upgrade to a modern version of php, with quite a lot of success.

While php 5.6 reached end-of-life as of December 31, 2018, WordPress’s step to make it the minimum allowed version while continuing to encourage usage of php 7.2 and above is an important one. For one thing, it means that securing installations will be just a bit easier, and for another, the minimum allowed version change, coupled with encouragement to use a truly modern version, as well as allowing plugin authors to specify a supported php version, will make life a lot easier for those of us maintaining code.

Most hosts, especially the larger ones, have already either migrated to php 7.2 or above, or are strongly encouraging their users to do so. Note that if you’re running a virtual private server or similar, you will be required to manage the php upgrade yourself. If you happen to be a user or organization running on a virtual private server, and you are not technically proficient enough to manage the upgrade, you’ll want to make arrangements for someone to upgrade for you. I mention this last point because in the laast few weeks I’ve run into a lot of cases where users or organizations have been talked into hosting on a virtual private server or similar which they are unable to manage and which they have no one to manage for them. I’m not sure if this is an actual trend or whether or not I’m just personally/professionally encountering a lot of these. Anyway, think of the web, and upgrade your php installation if you haven’t already.

After a user of the Storefront WordPress theme, (WooCommerce’s default theme), reported accessibility challenges with the theme’s focus outlines and text decoration with regard to links, the Storefront theme has been modified to address the issue with focus outlines by modifying the default outline so that it is darker than it was previously, as well as making the focus outlines solid. The theme will also underline links in the content, the footer, and breadcrumbs.

These changes are slated for the 2.5 release, which does not yet have a date set. However, you’ll want to keep an eye on your WordPress updates so that you can take advantage of these upcoming accessibility improvements. I’m looking at you, assistive technology sho[ps.

The 2nd Annual JavaScript for WordPress conference is scheduled for July 11 through 13 of 2019, and will include 3 FREE Days of workshops, talks and contribution all focused on JavaScript and WordPress. Workshops include learning how to use modern JavaScript development tools to write custom vanilla JavaScript in WordPress themes and plugins, as well as learning how to load and write React in WordPress plugins and themes. There’s a day of free talks separated into two tracks, and conference organizers have opened the speaker submissions. You can apply to speak and register for the conference on the conference page, as well as listen to past sessions. I was not able to attend this last year but will definitely catch up on past videos.

Rian Rietveld @ #WCUS:

Rian is demonstrating Voiceover and ARIA for the WordCamp audience.

She’s giving a very practical example of why semantics matter when it comes to the web.

Aria-live: Tells screen readers what’s changing on a page without refreshing the page.

aria-live allows dynamic changes to be announced by screen readers.

From earlier in the talk: First rule of ARIA: Don’t use ARIA. Use a native HTML 5 element first, then add ARIA *when necessary*.

Make sure when using aria-live that your announcement is not too verbose: For example: announce the number of search results, not every search result.

Overrule a link’s anchor text with aria-label. Beware: aria-label overrules a link’s anchor text completely. For screen reader users it’s as if the link text does not exist.

screen reader text class: Hide something from sighted users while announcing it to screen reader users.

Use screen reader text class with the span element.

Aria-describedby and aria-labeledby: aria-labeledby replaces label text, (see form elements), aria-describedby adds extra information to the label text.

Rian is able to turn VoiceOver on and off. This would never happen using Jaws. You can do it with NVDA though. Sorry, couldn’t resist.

Make it work before you make it nice.

Slides for this talk, code with examples is here, and you can watch “Who’s Afraid of ARIA” with captions here.

Miriam Schwab @ #WCUS:

Why is cryptomining from websites bad? Because it eats resources, plus governments shouldn’t be cryptomining.

Magic Cart: Going on for last three years, no one knows origination, attack ID’s third-party scripts on websites and then hacks scripts.

Magic Cart hacks scripts for the purpose of skimming credit card information.

Content security policies: white-list sources via browser header, if a source is not white-listed, it can’t be installed. Applies to trackers and other third-party web scripts like Google Analytics or Google Fonts.

Demonstrating code snippets which implement content security policies, will share slides later.

Includes log of violations of content security policies. I’m going to love looking at this code.

If you research content security policies online, not a lot of upp-to-date information, CSPs have been around since 2012.

W3C’s docs critiqued as being illegible, especially for those who speak English as a second language. Agree. Internationalization FTW!

Google is “do-as-we-say-not-as-we-do” with regard to its CSP docs V. what it does with its Google Analytics and other scripts.

Keeping up with what’s been added to pages manually is hard. Use Scrict Dynamic CSP instead. One policy across multiple pages.

Google has tools for CSPs: Strict Dynamic Test Bed, not sure of accessibility of tool will need to check later.

CSP can be added using meta tag or in theme’s functions.php file. Also .htaccess. Use these if you don’t want to work with browser headers. Probably can stick this in custom functionality plugin too.

CSP Mitigator from Google: Check http response headers, if no CSP present, will alert. If CSP present but there are problems with it, tool will offer suggestions.

There are also WordPress plugins for this, not recommended because some are out-f-date, but easy way to get started.

report-uri.com: Alternative to CSP Mitigater, useful if you have issues philosophical with Google.

Google’s resources making it possible for more people to implement CSPs.

Now demoing offline copy of White House website: No CSP, which means things can be injected client-side.

For the blind people playing at home, the injection to the Freedom scientific website changing the site tagline to “Too expensive products for the visually impaired” was a result of no content security policy being present on the site. Not from speaker, my own injection of another example.

Today marks the two hundred and ninth anniversary of the birth of Louis Braille, the inventor of the system of dots which bears his name and has enabled blind people all over the world, including myself, to read and write. This day is commemorated as World Braille Day, and in appreciation of the gift loaded with opportunities braille has provided me, I wanted to write a short note of thanks and gratitude as my Ultimate Blog Challenge post for today.

I’ve been a braille reader since about the age of five, and shortly after that, a braille writer. Braille was how I and my fellow students in the classes composed only of blind children I attended in my early school years learned to read, write, spell, and do math. I still enjoy reading braille whenever I can, using a braille display, and I honestly can’t conceive of my life without it. Braille has enabled me to contribute to the world around me, as well as cook, write code, and read for pleasure. Braille has made it possible for me to more concretely retain knowledge. I can learn by listening to either a screen reader or to an audio book, but there’s nothing quite like reading and then digesting as opposed to a near constant stream of spoken words that are coming in while the last ones I may have heard are still in the process of being internalized.

Several of the things I am sentimentally attached to involve braille: The box of birthday cards from my grandma which all have their messages in braille; the little porcelain shoes I received as a gift from Rian Rietveld at the final WordCamp U.S. with their attached note in braille; the purse charms I bought myself last year from elegant Insights Braille Creations with their embossed braille phrase. For me, nothing preserves memmories quite like braille does.

So, thank you, Louis Braille, for the privilege of being able to read and write, and thereby contribute to my world. Thank you for the enjoyment, and the ability to read when the power’s out, and the ability to capture memories in a way that will outlast almost every form of technology. Thank you for everything.