WordPress Web Design

WordPress 7.1, a New Browser Extension, and the Real Cost of Bot Traffic: What Agencies Need to Know This Week

wordpress is moving fast this month. A major core release lands on 19 August, an official browser extension has quietly shipped, and fresh data on bot traffic is forcing every serious agency to rethink bandwidth budgets. Here is what our team is tracking and acting on right now.

Key Takeaways

  • WordPress 7.1 introduces client-side media processing, expanded design tools, and the new Abilities API — all shipping 19 August.
  • The official WordPress Browser Extension is live for Chrome, Chromium-based browsers, and Safari on macOS, streamlining admin workflows.
  • Kinsta’s analysis of over 10 billion HTTP requests reveals bots are silently inflating hosting costs on WordPress sites at scale.
  • Robots.txt, llms.txt, and active bot protection each control AI crawler access differently — and none of them alone is enough.
  • Spam remains a persistent drain on WordPress site performance and credibility, but layered defences make it straightforward to manage.

WordPress 7.1 Brings Client-Side Media Processing and the Abilities API

We have been testing the beta builds, and two features stand out. Client-side media processing shifts image compression and resizing to the browser before upload, which cuts server load and speeds up editorial workflows for content-heavy client sites. The Abilities API gives developers a standardised way to query what the current WordPress environment supports, making plugin and theme code cleaner and more portable.

Design tools also get meaningful upgrades. Our front-end team is already mapping these into our starter themes so clients benefit on day one. Agencies that delay adoption risk falling behind on page speed and editorial efficiency. Full details are covered in Kinsta’s deep-dive on everything new in WordPress 7.1.

The Official WordPress Browser Extension Ships for Chrome and Safari

WordPress.org has released an open source browser extension that lets logged-in users hide the admin bar while keeping its most useful shortcuts accessible. It is available now in the Chrome Web Store and the Mac App Store for Safari.

For our team, this is a small but welcome quality-of-life improvement. Designers reviewing front-end layouts no longer need to toggle the admin bar in user settings. Developers get quick access to edit links and cache-clearing tools without visual clutter. We are rolling it out across our internal workflows immediately, as outlined in the official announcement on WordPress.org.

Bot Traffic Is Quietly Draining WordPress Hosting Budgets

Kinsta analysed more than 10 billion HTTP requests across its infrastructure and found bots hit add-to-cart URLs on WordPress sites 7.67 million times. That is real bandwidth consumption that never appears in standard analytics dashboards.

We have already started auditing server logs for every WooCommerce client to quantify wasted resources. The fix is not a single plugin — it requires a combination of server-level rules, rate limiting, and intelligent caching. If your hosting bill has crept up without a traffic increase to match, bot activity is the likely culprit. The full dataset is available in Kinsta’s research on the hidden cost of bot traffic on WordPress.

Robots.txt Alone Will Not Stop AI Crawlers

A common question we hear: “Does robots.txt block AI scrapers?” The short answer is that it asks them to stop. It does not force them. The newer llms.txt standard is designed to give AI models structured access guidance, but compliance is voluntary. Active bot protection at the server or CDN level remains the only enforceable layer.

Our recommendation is to use all three in combination — robots.txt directives, an llms.txt file where appropriate, and server-side blocking rules. We have integrated this layered approach into our standard maintenance plans, a strategy aligned with Kinsta’s breakdown of what actually controls AI access.

Layered Spam Protection Remains Non-Negotiable

Spam on WordPress is not a new problem, but it remains a persistent one. Comment spam, fake registrations, and contact form abuse all erode site credibility and waste admin time. We deploy a layered stack — honeypot fields, server-side validation, and selective CAPTCHA — across every client build. The step-by-step methods are well documented in WPBeginner’s 2026 WordPress spam protection guide.

This week’s developments reinforce a consistent theme: WordPress agencies that automate maintenance, monitor server logs, and adopt core updates early will outperform those that treat the platform as set-and-forget. We are adjusting client roadmaps accordingly.

Frequently Asked Questions

What is the WordPress Browser Extension and how does it help site managers?

It is an official open source extension for Chrome and Safari that hides the admin bar while preserving quick-access shortcuts. It lets designers and developers review front-end layouts without visual interference from admin UI elements.

How do web designers prepare for WordPress 7.1’s new features?

Start by testing themes and Plugins against the 7.1 beta in a staging environment. Pay particular attention to client-side media processing behaviour and any custom code that queries server capabilities, as the new Abilities API changes how those checks work.

Why does bot traffic increase WordPress hosting costs?

Bots generate real HTTP requests that consume bandwidth and server resources, even though they never convert. Hosting plans billed on visits or bandwidth will reflect this invisible load, making regular log audits essential.

What is the difference between robots.txt and llms.txt for controlling AI crawlers?

Robots.txt is a long-standing standard that requests crawlers not to access certain paths; llms.txt is a newer file that provides structured guidance specifically for large language models. Neither is enforceable on its own — server-level bot protection is the only reliable blocker.

Local Friendly Web Designers - waiting to make you happy

Need help? - Get a Quote in under a minute

See what people say about our web services