Client Survey Results 2022: Superb Website Speed and Security

client survey results 2022

The results from our traditional annual client survey are here! Looking back at 2022, we’ve been working hard to introduce new and improve existing tools and services that make your websites even faster and safer. But at the end of the day, what really matters is the impact of these improvements and the positive effect they brought for our users. Here is what you had to say and how you rated our efforts and your experience with our hosting services throughout the past year.

An Outstanding 98.8% Satisfaction with Site Security

Securing your websites has always been a top priority for us during the years. 2022 was not an exception and our efforts didn’t go unnoticed – our Website Security was rated high by an overwhelming 98.8% of all respondents! Here’s what we did to achieve that:

We improved our already great-performing Site Scanner with features improving early malware detection and introduced a new plan with proactive reaction tools in case of a website attack. During our #CyberSecurityMonth campaign last October, we went even further. We not only ran an intense email awareness campaign about website security, but we also introduced new security features, such as an on-demand IP and Geo traffic blocking tool. We also improved our AI-driven brute-force prevention system and its state-of-art self-learning mechanism, which now blocks over 95% more bad traffic before it even reaches our servers. Here’s a recap of all essential website security features for your website, in case you’ve missed it.

Last but not least, towards the end of 2022, we launched our new monthly security reports, included for free with all our plans. You can now sign up and receive directly in your inbox a personalized security overview of your website(s) every month, with highlights of what security measures we’ve applied and suggestions of what you can improve.

A Supreme 97.7% Satisfaction with Website Loading Speed

Website loading speed is important for your conversion rates, SEO rankings, and users’ experience. That’s why boosting website performance is of utmost importance to us and we’re constantly working on making your websites as fast as possible.

As early as February 2022, we introduced a newer version of our SiteGround Optimizer plugin for WordPress, making it available and free to all WordPress users, regardless of where they host their websites and included new advanced speed features, such as file-based caching. The plugin now has over 1 Million active installations and was voted Silver in the top 3 best WordPress optimization plugins in the annual WordPress community awards. 

One of our biggest speed-boosting achievements in 2022 was the launch of our in-house built SiteGround CDN which not only makes websites load blazingly fast around the world, but it’s super simple to configure in a few clicks and included free in all our plans. We didn’t stop there and kept on growing our CDN and data center networks with a new location in Madrid and a few new locations in the USA.

Top Marks for Easy Website Migration and Setup

We’re happy to welcome those of you who have recently joined SiteGround as clients.

48.6% of our new clients say that the number one factor that led to the decision to get on board was a recommendation for SiteGround by someone they trust. 44.4% of you point out positive reviews about SiteGround were what influenced your decision to choose our hosting services, which is the greatest mark for the level of quality we provide, and the recognition and loyalty of our clients. 

Your feedback about how easy our onboarding process is was also extremely valuable. A total of 78.3% of you, who created a new website with us, have noted that setting up a website on SiteGround was a hassle-free process. 76.9% of you, who switched over from another host, pointed out in the survey that transferring your websites to us was a seamless process.

Now it’s even easier to migrate and manage all elements of your website presence to SiteGround with our newly launched Email Migrator tool. It helps you transfer emails to SiteGround servers easily, securely, and automatically.

We’re looking forward to making your future experience with us even better and contributing to your websites’ success.

A Steady 98% Overall Satisfaction In the Last Few Years

We completed 2022 with an overall client satisfaction rating of 98.1% which solidifies our top-rank customer happiness rate in the last couple of years. The overall satisfaction rate is based on your reviews for the following services we provide:

The breakdown of the satisfaction rate of each aspect of our services is based on the evaluation of both long-term and new clients. The overall ratio of all respondents is 90.40% long-term clients and 9.6% clients who have joined in the past 12 months. The fact that the majority of respondents have been with us for a couple of years now, and continue to express their satisfaction with our services with top marks is the greatest recognition a company can have.

You Helped the Environment by Completing Our Client Survey

Just like everything else we do, we also tried to maximize the impact of our client survey this year. In return for completing it, we committed to donate funds for planting a SiteGround forest. Thanks to you, we’ve already planted more than 11,000 trees worldwide – in the USA, Spain, Portugal, France, Indonesia, Madagascar.

We’d like to thank you for your trust, for your feedback, and for helping the environment! Stay tuned for all the upcoming services improvements and new tools launches that will aim to make your websites even more secure, better-performing and successful in 2023.

[subscribe_cta]

Kickstart Your Business with SiteGround’s New Email Course

Start Your Business Online Email Course

The new year is here, and what better way to start it off right than turning a business idea into reality? You can do just that with SiteGround’s new email course – Start Your Business Online in 2023. This comprehensive course will teach you everything you need to know to get your business up and running – from ideation to execution. 

What does the course cover? 

This email course provides a step-by-step blueprint for successfully launching a business. Over a month, you’ll receive eight in-depth emails that will teach you how to:

  • Validate your idea and define your target audience
  • Develop your brand identity
  • Craft your SEO strategy
  • Build, customize, and optimize your website
  • Launch your project and start growing

The email course comes with a bundle of downloadable assets and additional resources to help you throughout the learning process. By the end of the course, you’ll be ready to launch your dream project. 

Who is this course for?  

This course is perfect for entrepreneurs of all experience levels looking to start their own business. Whether you’re starting from scratch or need guidance on where to go next with your existing project, this course will provide invaluable insights tailored to help power up your inner entrepreneur. 

Win free hosting!  

We believe in the power of new ideas to drive business success. That’s why, as a special bonus, five people who sign up for the course in January will receive one year of free hosting from SiteGround. 

So don’t wait any longer – start your business in 2023 with SiteGround’s email course and make your dreams a reality. Your future success is just a few clicks away!

>> SIGN UP NOW

[subscribe_cta]

Start Creating Content with WordPress (Webinar Q&A)

start creating content with wordpress

We recently hosted a webinar on how to create content online with WordPress. The session is the second one in a series of walkthroughs aimed at helping content creators and website aspirants build or improve their online presence.

The webinar recording is available on our official YouTube channel for those interested in getting started with a WordPress website, or brushing up on their knowledge:

We also got a great deal of interesting questions which we didn’t have the time to address during the webinar, so we’ve provided the answers in the blog post below.

First Steps in WordPress Site Management

How do you customize my URL, so it just has my own domain and doesn’t include “wordpress”?

It seems that you are hosting on WordPress.com and using a free wordpress.com domain name, hence the wordpress keyword in your domain name. You should be able to purchase a custom domain and change it from your WordPress.com control panel.

If you move to a paid hosting provider such as SiteGround, you can register any domain name you wish as long as it’s not taken by someone else, and easily set your site to be accessible by that domain.

The key factor here is that the SiteGround.com portal and the Admin panel of your website are two different areas. By accessing your SiteGround Client Area, you can manage all your sites and payments, and access site-specific tools such as backups, emails, etc. The wp-admin page will lead you to log into your WordPress Admin panel to edit and customize the content of a specific site. To access your SiteGround Client Area, you need to go to login.siteground.com and type your SiteGround username and password. They may be different from the ones you use for accessing your WordPress Admin, so if the system does not accept them, you can use the Login recovery option available on screen.

How do I go about adding a new site to my plan on SiteGround? When is it advisable to have multiple sites? 

All hosting plans we offer, except for the StartUp package, allow you to create and manage multiple websites. To create another site under your account, simply access your Client Area > Websites > Add new and go through our Website Setup Wizard. It takes just a few minutes to spin off new sites using the wizard and we have depicted the whole process in these guides.

It’s advisable to create an additional website in case you have a plan of what you want to use it for and, of course, time, as you will need some extra effort to develop and maintain the site. If you want to write on a totally different topic or start a completely new project, then it’s a good idea to create a new site for it.

Customizing your WordPress Site

Can I publish/display a “coming soon”/”under construction” page as the Home page while I work on my website in private?

In case you haven’t started your site yet, you can always create it on a temporary url provided by SiteGround which is not indexable by search engines (so random people on the web can’t find it accidentally) and later change it to your real domain name. By doing this, you won’t have to worry about installing additional plugins or doing additional configuration.

If you already created your site, one of the easiest ways to create a “Coming soon”, “Under Maintenance” or similar landing page is by using a plugin. It will allow you to design the page using a template and show it to your regular site visitors, while you will be able to access your dashboard and work on your site as usual. Once you’re ready to go live, you can easily disable the page and show the expected content. There are multiple Maintenance plugins available for free in the WordPress repository and one of the best documented is SeedProd.

You can read about alternative ways of hiding your site in our article on how to limit access to website during development.

If I have some pages that I only want subscribers to see, how do I control the login process?

Depending on your final objective, you have a couple of options.

The simplest way that does not require any plugins or whatsoever is to set your desired pages to require username and password to be accessed. This way only website users who have the necessary credentials may be able to view the content on the page. You can password protect your pages from the native WordPress Password Protected option described in our tutorial on adding pages to WordPress. Among the downsides is that there is no automation, in other words you will have to provide the credentials manually to each user.

If you are looking for more robust options for turning WordPress into a community site, you can install a Membership plugin. It comes with elaborate options that you can set to your preference, including enhancing the registration process and personalizing the login screen and dashboard. One of these plugins is BuddyPress and you may read more about it in our tutorial.

How can we add more themes to WordPress?

Additional themes can be installed from the WordPress Admin panel > Appearance > Themes > Add New. You can check our tutorial for step-by-step instructions or watch the webinar from this moment, if you prefer to see the steps.

If we change themes and there are some leftover images and text of the first theme, how can we remove them and troubleshoot this issue?

This looks like a development question, related to the specific site setup, but generally changing your theme should not affect your image and text content because the latter is added by you, while the theme is only responsible for the overall appearance of your site.

If you are referring to demo/imported content from the previous theme that you don’t need, you can either delete it manually from your posts/pages/media library or if you want to start literally from scratch,  you can delete WordPress, reinstall it from Site Tools and apply the new theme.

Can I embed code from another site for my contact form?

You can copy and embed code from a different site into WordPress, but this usually requires advanced coding skills to configure properly. Most of the time, it’ll be easier to check if the other site offers a plugin for better integration. 

Should I ask for the contact plugin from the email provider I will use?

The actual contact form setup depends on the email provider you’ve chosen. If you are using a business email provider (SiteGround offers business email service on all hosting plans at no additional cost), it’s likely that they do not offer a contact form plugin as it’s not within their scope. This is the more common scenario and what you can do is download and use a free third-party contact form plugin from the WordPress repository and set it up with your business email address. The one that we recommended during the webinar was WPForms and it has detailed instructions on how to create a contact form and add it to a page.

On the other hand, there are email marketing platforms that come with a greater toolkit for managing emails, but usually have a corresponding cost. If you’re using such a service, then it probably offers a plugin that lets you easily integrate the contact form you create on its platform with your own site. You would find information about their plugin, instructions on how to use and get support directly on their website.

Do you recommend using Divi/Elementor? If so, could you do one of these workshops on how to best use it?

With WordPress, you get a built-in block editor that is capable of both formatting and editing content, and our Start creating content with WordPress webinar covers exactly that. Divi and Elementor are addons that work on top of this native framework with some caveats among which is the fact that each comes with its own learning curve, which will require additional time and effort to master. Certainly, you can use them, but it’s best to get a better understanding of the basic WordPress framework before using any addons, partly because these addons largely revolve around it as well.

Check out our YouTube channel for an introductory webinar on Divi.

When Your WordPress Site is Ready to Go Live

Is the HTTPS protocol enabled automatically for WordPress websites?

Securing your website with HTTPS protocol is essential. We install an SSL certificate automatically for free on all new websites as long as the website is resolving from our servers. WordPress requires an additional step required before your site loads with HTTPS – to reconfigure your urls and enforce the HTTPS protocol.

We do not automate this, as it is a webmaster decision that we cannot make on behalf of the owner of the site, but we have developed a tool that allows you to do it instantly. If you are already using the SiteGround Optimizer plugin, access its Settings > Environment settings > HTTPS Enforce. In rare occasions, some of your site elements (most often images) may still load with http leading to the so-called mixed content issue. If this happens and your site does not appear as fully secure, toggle also the Fix Insecure Content option. More details can be found in our article.

How do I connect Google Search Console to my site?

To add your site to Google, you will need to verify that you are its owner. This can be done in several ways, but one of the easiest methods, if you are a SiteGround customer, is to create a TXT record in your Site Tools DNS Zone Editor. You’ll be able to get the TXT record during the setup. 

Head to the Google Search Console website to get started and check out their official guide for step-by-step instructions.

Will you be doing a webinar on e-commerce on your site?

We’re passionate about eCommerce and we’re definitely considering it. Meanwhile, you may want to check out some of our previous webinars on using WordPress as an eCommerce tool, such as our step-by-step walkthrough on setting up WordPress as a store with WooCommerce.

[subscribe_cta]

2022 Wrap-Up: Unlock our Milestones and Win

2022 year in review at SiteGround

2022 is coming to an end, and here at SiteGround, we marked another winning and eventful year. We worked hard on enhancing our services and tools and fine-tuning our hosting environment to be even faster and safer for our clients.

Now it’s time to wrap up and look back on the whole year! Go to our 2022 Recap, unlock our milestones, collect points, and enter to win a pair of custom noise-canceling BOSE headphones!

>> Go to 2022 in Review

Technology Optimizations for Faster and More Secure Websites

In the past year, we took our hosting environment security and speed to yet another level. Some of the service enhancements and cutting-edge tools we launched are: 

Improved WordPress Tools For All

Our custom plugins for unmatched WordPress speed and security – SiteGround Optimizer and SiteGround Security – have together been installed nearly 3 Million times already. This year marked another big step on this journey, after we released both plugins for free use by everyone, regardless of the hosting platform you are using. In less than a year, SiteGround Optimizer has had more than 1,000,000 active installations on top of the 2+ Million SiteGround users and is ranked among the top 3 performance optimization plugins. The SiteGround Security plugin is close to 1 Million new installations and is ranked as one of top WordPress security plugins by the community.

In 2022, we also increased the WordPress memory limit for all of SiteGround clients in response to a growing demand in the community for raising the default WP memory value and to accommodate the ever-growing development of WordPress sites. The new limit of 256 MB on our servers means our WordPress clients have more room to expand their WordPress sites right out of the box.

Expanded Data Center and CDN Network

In 2022, we introduced 4 new Data Centers and 7 CDN locations across Europe and the USA. Our new geographical locations provide better website performance and faster content delivery. 

Our clients can now host their websites as close as possible to where their visitors are to ensure faster page loading time and better user experience.

98% Client Satisfaction Rate

Being customer-driven has always been a cornerstone for us. Our clients’ feedback is the driving force behind everything we do at SiteGround. For this reason, each year we ask our customers to rate our efforts and services throughout the year. 

This year our client satisfaction rate remained a steady 98% on our annual end-of-year survey. And to share our gratitude for our customers’ input, we’ll plant a tree through TreeNation for each person who completed the survey.

Explore Our Milestones and Win Bose Headphones

Revisit these and more annual accomplishments in our SiteGround Year in Review and enter our raffle for a chance to win a pair of custom noise-canceling BOSE headphones! And that’s not all – get extra entries by sharing our recap on social media with #SiteGround22 by January 9, 2023!

2023 is around the corner – supercharge it with some extra points from 2022 and SiteGround, and let’s see what it has in store for us!

>> Go to 2022 in Review

[subscribe_cta]

New Monthly Security Reports Now Available

SiteGround Monthly Security Reports

Do you know how secure your site is and if its security level is changing over time? Have you ever wondered how many actual attacks toward your site are being mitigated? Do you want to know if you have missed doing something easy that may protect your site from incidents? 


Now with SiteGround’s Monthly Security Reports, you can get all that information and more – straight to your inbox. Just sign up and start receiving an actionable monthly report covering what SiteGround is doing to safeguard your site and highlighting security measures that you may have overlooked.

What’s in the Monthly Security Reports?

Each month we will perform automated security checks for your website covering malware protection, SSL certificates, software exploits, brute force attacks, and other security areas. Based on our checks, you’ll receive a digestible summary of the results – including a total site security score, breakdown score for each security check, and actionable tips if some area needs your attention. The monthly security reports will be your go-to place to get an overview of your website security status.

The benefits of the Monthly Security Reports 

Site security information in one place

Performing website security checks manually can be an investment of valuable time, effort, and money that most website owners can’t commit. With the monthly security reports, SiteGround will handle the heavy lifting for you, performing all necessary security checks and delivering user-friendly reports straight into your inbox. So you get to know everything with no effort required on your side. 

Easy to understand format

With our user-friendly design, you can quickly scan the report and easily identify areas that need your attention, if any. All you have to do is follow our straightforward color codes:  green when everything is good; yellow: needs improvement; red: definitely needs attention. You also receive an overall score for the month and information how it has changed in comparison with the previous month.

Actionable advice when needed

If we have identified an area of your site security that may be improved, the report will include easy-to-follow instructions on what can be done. For example, if we detect that you don’t have an SSL certificate installed on your site, it will provide you with a link to the information on how to set it up.

Confidence that your website is protected

By signing up for our monthly security reports, you may easily monitor what we do on a regular basis to keep your website safe. Each month you will see information like: how many software vulnerability attacks have been prevented; how many malicious IPs were stopped from reaching your site; how many backups you may count on, etc. Making sure your site is secure is an enormous part of our job as a host, and with the reports you can keep an eye on this process.

How to get the Monthly Security Reports? 

Starting from next year we will gradually begin to proactively send the reports to all our clients. However, you may hurry up and sign in yourself today and be among the first to receive their report in early January 2023.

To subscribe for your report now, just go to: Client Area -> Notification Preferences -> Monthly Security Reports.

The reports are sent out at the beginning of each month for sites that have been active for more than 30 days and have their domains pointed to SiteGround. You can see detailed information on subscription, content and score calculation in our Security Reports Explained article. 

Sign up today and sleep soundly, knowing that all relevant site security information is right at your fingertips.

[subscribe_cta]

PHP 8.2 Is Now Stable and Available on SiteGround Servers

stable release of php 8.2 version

PHP 8.4: Stay Updated! 🚀 Check out our latest blog post to explore the newest features and enhancements in PHP 8.4.

It’s that time again! Time for the Santa ElePHPant to visit all the good little PHP developers around the world and shower them with new goodies that make it easier for them to build the web.

As of this writing, PHP 8.2 is in Release Candidate 1 (RC1) status. We are in the late stages of development and bug fixing for this version and you can tell because forward looking web hosts like SiteGround are now making the RC builds available for their clients to test with. (Did you see the word TEST there? For those who don’t know what that means, it means NOT IN PRODUCTION!)

So let’s take a look at some of the new presents that Santa ElePHPant is bringing us.

New Goodies

First up, let’s take a look at a few of the new features that will be of interest to PHP developers. This is not an exhaustive list of the new goodies in Santa ElePHPant’s bag. It’s more a short list of the things I think the majority of PHP developers will be interested in.

readonly classes

In PHP 8.1 we got readonly properties for classes. This was a great leap forward for a lot of projects. However, there is still a small hole that needed to be plugged, clases. Yes, you can make every typed property in a class as read only and you are good to go, but honestly, that’s a lot of typing and if we know anything, we know that developers are lazy. So instead, in PHP 8.2 we can mark an entire class as readonly.

readonly class MyClass {
    public int $myProp;
    public string $myOtherProp;
    public __construct(string $myOtherProp, int $myProp) 
    {
        $this->myProp = $myProp;
        $this->myOtherProp = $myOtherProp;
    }
}

Here we have a class defined as readonly. We have 2 properties of the class and both of them are inherently readonly. The readonly rules from PHP 8.1 still apply. You can initialize the property only once, after that it is set. 

$myObj = new MyClass(‘Cal was here’,42);

However, once they are initialized, they are now immutable.

$myObj->myProp = ‘Cal is no longer here’;

// Fatal Error: Uncaught Error: Cannot modify readonly property MyClass::myProp

One other behavior of the readonly class is that properties cannot be dynamically added to the class, ever. Below we talk about deprecating Dynamic properties and how that’s a good thing. There is even an annotation that allows you to override this. However, if you mark a class as readonly, then it cannot be overridden.

Constants in Traits

Traits have been with us in PHP since PHP 5.4. They have long been the language’s answer to “composition over inheritance”. Now traits are getting an interesting new feature, the ability to define constants in a trait.

trait MyTrait {

    private const MY_CONSTANT = 42;

}

Now, if your trait uses a constant, you can define it in the trait and not have to remember to define it in each class that uses the trait.

trait MyTrait {

    private const MY_CONSTANT = 42;

    public function meaningOfLife() : int

    {

        return self::MY_CONSTANT;

    }

}

class MyClass {

    use MyTrait;

}

$myObj = new MyClass();

echo $myObj->meaningOfLife(); // prints 42

Like everything in life, there are a few rules.

Traits can define class constants. If a class uses that trait it can also define the same class constant as long as both the visibility and value are exactly the same. So the example above works but the one below will trigger a fatal error

trait MyTrait {

    private const MY_CONSTANT = 42;

    public function meaningOfLife() : int

    {

        return self::MY_CONSTANT;

    }

}

class MyClass {

    use MyTrait;

    public const MY_CONSTANT = 42;

}

Still, even with the rules that you have to follow, this is a real step forward. Traits are a great way to share code between classes and now they are even more self-contained.

Random Extension 5.x + Random Extension Improvement

The original PHP random number generator is still in the base code. It’s never been great and it’s absolutely useless for cryptographic uses. In PHP 7, we got a couple new functions, random_int() and random_bytes(). They went a long way to fix the problems but under the hood, they are just interfaces to the native OS’s random number generator. At the time this was a good solution but the problem is it’s a slow one. 

Now with PHP 8.2 we get not only an entirely new Random number generator, it is built into PHP,  and we get an extensible object oriented interface to it.

This is actually two different RFCs that I’m lumping together. After the first one “Random Extension 5.x” was voted on and passed, it was discovered that there was a few issues with it. A second RFC, “Random Extension Improvement”,  was prepared and voted on to fix the issues found with the first one.

The end result is a new set of classes that give us better pseudo-random numbers in PHP.

While we are actually getting several new random number generators (RNG), for simplicity I’ll discuss the new Random\Engine\Secure class.

$engine = new Random\Engine\Secure();

$randomString = $engine->generate(); // a random binary string

echo bin2hex($randomString); 

Now if we want to do something like sort an array, we need one of the new Randomizer objects. 

$randomizer = new Random\Randomizer($engine);

$items = range(1, 10);

$randomizedItems = $randomizer->shuffleArray($items);

print_r($randomizedItems);

Now in the above example, we used the Secure engine. The secure engine does not accept a seed and will always generate a non-reproducible string. The engines that allow you to specify a seed will produce the same results each time if you use the same seed. 

The Randomizer class also provides several other methods that are really what PHP developers are looking for.

  • getInt() : int
    This replaces the old mt_rand() function
  • getInt(int $min, int $max) : int
    This replaces both the old mt_rand() function as well as the newer random_int() function.
  • getBytes(int length): string
    This replaces the random_bytes() function 
  • shuffleArray(array $array): array
    This replaces the old shuffle_array() function
  • shuffleString(string $string): string
    This replaces the old str_shuffle() function

Among other things, since this brings all of the randomizing functionality into a single area of the engine, it streamlines the core code and will make further improvements easier.

“So long and thanks for all the fish”

All good things must come to an end and that includes some features and commands of PHP. Let’s look at a couple of the important deprecations that if you aren’t careful will end up causing you problems.

Deprecate dynamic properties

At first blush, this one seems like it’s going to be a huge problem. Since PHP got the current object model, it’s been possible to add properties to an object any time you want. Now somebody thinks this behavior is a bad thing. (HINT: It was always a bad thing but one a lot of developers took advantage of.)

class MyClass {

    public string $name;

}

$myObj = new MyClass():

$myObj->nmae = ‘Cal Evans’;

Notice that I misspelled the property name. I know I’m probably the only developer who has misspelled a property name but in PHP when it happens, I get a new property on the object and the original property remains unchanged. That was not my intent.

Starting with PHP 8.2, this will emit a DEPRECATED WARNING.

There are 3 exceptions to this new rule.

  1. Any instance of StdClass will still be able to accept dynamic properties.
  2. Any class with magic __get() and __set() methods will still accept any property.
  3. Any class that has the compiler annotation #[AllowDynamicProperties] and any child class will allow dynamic properties to be set.

So while all is not lost for those that depend on this “feature” of PHP, if you are still going to use it, you are going to have to make some changes to your code. 

The good news is that all that will happen right now is the warning emitted to the log files. So while it might fill up your log files reminding you that you need to fix this, PHP 8.2 won’t break your code. That happens in PHP 9.0 when the warning – and the ability to automatically add dynamic properties – gets removed from PHP.

(Partial) Deprecate ${} string interpolation

This is another depreciation that on the surface I thought was going to be a huge deal. Turns out, it is probably not going to affect many developers.

There are 4 ways to implement the “{$variableName}” syntax, 2 that make sense, and two that don’t. The two that don’t are going away.

echo “$meaningOfLife”;

By far, this is the most common version of string interpolation. Just put the variable in a string with double quotes. If you are doing this, you are fine, this is one of the two ways that are staying.

echo “{$meaningOfLife}”;

echo “{$dogulasAdams->meaningOfLife()}”;

I always considered this way “old-skool”. Yeah, we used to do it way back in the day but I’ve not done it this way in a long time. Still this works, it’s clean, and it’s easy to understand. This is the other one that is staying.

This is also the only method that allows you to use object properties and methods. So if you want to use string interpolation with an object, you will need this method.

echo “${meaningOfLife}”;

This one is going away. Yes, it does the same thing as the first two, but it is a little more confusing because the $ is outside of the braces. 

$fourtyTwo = 42;

$meaningOfLife = ‘fourtyTwo’;

echo “${meaningOfLife}”;

Finally, we have the way that you can use “variable variables” from within string interpolation. This is just too many levels of indirection. In the code above, we eventually get to the point where we echo out 42, but we take the long way around. 

Starting in PHP 8.2, the last two structures will emit a DEPRECATION WARNING in your log files. In PHP 9.0, they will stop working altogether and cause your program to crash. (or throw an Error that you can catch, but probably can’t recover from.

Wrap Up

This is the first PHP 8.2 Release Candidate. Don’t play with it on any production site. If you want to test it with an existing site, set up a new site for testing, clone your production site into it, and play with that. When you are done, you can just delete it. 

As you poke around in your new testing environment, check your log files after every test. Make sure nothing fails and see if any new WARNINGS pop up. 

If PHP 8.2 is anything like PHP 8.0 and PHP 8.1, I don’t expect modern PHP code to have issues with it. Thankfully, Santa ElePHPant’s Elves that work for SiteGround make it incredibly easy for you to test things out to make sure your site can run as fast as possible with PHP 8.2

Speaking of performance, PHP 8.2 hasn’t been properly benchmarked yet, but we have come to expect every version of PHP to be a little faster than previous versions. With changes to the CSPRNG system and other things like removing the old libmysql, it’s a safe bet that this version will be faster than PHP 8.1.


While you are testing, cloning, and observing results, make sure you take time to tweet out a huge THANK YOU to Santa ELePHPant and all of the little ElePHPant Elves that made this release possible. Rumor has it that they keep an eye on twitter.com/@php_net

To celebrate the latest release candidate PHP 8.2, we are giving away 5 exclusive SiteGround PHP elephant plush toys (a.k.a Groundy) in a raffle, running from September 8, 2022 until September 11, 2022. Read more on Twitter.

[subscribe_cta]

Moving to a State-of-the-art, In-house Built Spam Protection Solution

email spam protection service

When you’re busy processing tons of emails each day, and we all are, the last thing you need is a bunch of spam messages sneaking into your inbox. Spam protection has always been an important part of our email service and in our strive to constantly improve it we are now introducing a new in-house built solution. It is designed to efficiently minimize the amount of SPAM emails delivered to your inbox, while constantly learning from your email reading behavior. It is also built specifically for our clients and works seamlessly as part of our hosting environment.

Efficient and easy to use for our clients

Less SPAM messages delivered to your inbox

Based on our multiple years of managing email services, we have created a system that decides with a high amount of accuracy which messages are legitimate and should reach your inbox, which are suspicious and should be delivered in your Junk folder, and which are outright dangerous and should not reach your email at all and will bounce instead.

Your email reading behavior trains the system

Your natural actions, while working with your mailbox will train the system. Whenever you move a message to or from your Junk folder you will improve its accuracy. Based on your action the system will add your personal perception of what is SPAM on top of its own underlying rules. Thus your feedback is taken into account seamlessly, without a need for you to use an additional SPAM management interface.

Easy interface to allow and block senders

And also, if you would like to tell the Spam protection system directly how to treat a certain sender, you can still use our easy interface to block or allow specific senders. By adding an email address or an entire domain to the Block or Allow List you indicate how you want this sender to be treated by the system. Check the following tutorial on how to use the Spam Protection service in Site Tools.

Better control and easier scalability for us

We may address our clients’ needs 

By using an in-house solution we can more easily address our clients’ specific needs and introduce new features and improvements faster. For example, we have noticed that the current setup makes it difficult for our users to find out when a legitimate email is not delivered to them and is marked as spam by the system. This happens because the message is placed in a quarantine folder in a separate tool that is not part of the user’s natural email management. With the new solution we were able to address this issue by using the much more visible Junk folder instead.

We may handle email usage spike better

When we manage the spam protection system as part of our own infrastructure, we can easily scale it. Even if there is a steep global increase in the email traffic we can seamlessly add the resources needed for the evaluation of the excessive messages. Thus the email delivery will not be delayed for our clients, regardless of the unexpected usage spike.

How to use SiteGround Spam Protection?

All SiteGround clients have our state-of-the-art Spam Protection features enabled by default.

[subscribe_cta]

New Email Migrator Tool for Fast and Easy Email Transfers

migrating email messages from one server to another

When changing your hosting provider, sometimes it is not only about moving your website and pointing your domain to the new server. If you also use email services as part of your hosting plan, the most challenging part of the process may be transfering your email accounts and messages without losing data or creating disruption to your business communication process. To address this challenge for people, who prefer to have everything hosted at one place, we have now added a new Email Migrator tool. It allows you to transfer your mail service from another server to our mail servers fast, easy and securely.

Why did we develop the Email Migrator

SiteGround clients who are transferring from other hosting providers already benefit from our automatic website transfer options. The Email Migrator tool streamlines this process even further, making the transfer of email services possible in just a few clicks, even by not so tech-savvy users. On top of that, the tool helps you keep your email communication intact and safely transfer all of it to our servers.

What are the benefits of our Email Migrator tool

In addition to making it easier to transfer your emails to SiteGround and have everything in one secure place, our Email Migrator has a couple of other added benefits:

  • Intuitive interface for easy migration start 🏗️

The tool interface guides you through the few steps needed to get the process started.

  • Secure and reliable transfer 🛡️

We’ll move your emails in a secure manner, ensuring privacy and data protection.

  • Fast migration 🚀

We’ve developed the tool in a way that the procedure won’t take too long. Yet, the exact time needed will depend on different factors, such as the size of the mailbox, remote server speed, and others.

  • Keeping the structure of the email account being migrated 📧

We’ll transfer your email account for you, including folders, messages and attachments.

  • No duplicates created 📑

We’ll make sure that there are no duplicates created during the migration process.

  • Automated process 🪄

There’s no manual work required on your end, as the migration happens in the background. You’ll need, though, to set up the systems that are beyond SiteGround control: point your MX records to make the new messages come to our server and reconfigure your email client to start receiving the messages from our server.

How to transfer your emails with the Email Migrator

To transfer your emails, you need to follow a few simple steps in your Site Tools > Email > Email Migrator. Read detailed instructions on how to transfer your emails and enjoy a hassle-free email migration to SiteGround!

The Email Migrator is basically the last piece of the puzzle that lets you have everything in one place. Transferring all things to SiteGround allows you to easily manage both your website and email in one account. Not only do you have everything in one place, but you’re counting on our proven expertise in both web hosting and email services.

[subscribe_cta]

Don’t Fall for Email Scams This Black Friday

phishing emails during Black Friday

The infrastructure that runs the Internet’s email hasn’t changed a whole lot in the past 30 years. Yes, we’ve layered a few things on top of it like Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) but at its heart, the protocol remains the same. That’s the problem. Email was designed in a simpler time. A time when the Internet was a trusted resource and nobody gave a second thought to the fact that it’s easy to say fudge the headers on an email so that it looks like your boss is getting an email from the President of the United States commending you for all your excellent work. I’m not saying that has happened or that I was a part of it…but hypothetically, it is possible.

So, if email can’t be trusted, what can we do? Well first, these days email is a lot more trustworthy. It is much easier to detect emails sent from someone, but say they are from the President, thanks to things like Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM).

Even with these new technologies though, email scams are still rampant. As we charge headlong into the holiday season, let’s stop for a moment and look at a few things you can do to make sure you don’t fall for the latest scam. (Which is not sending emails to unsuspecting bosses…)

Email Scams You Need to Be Aware Of

Let’s take a look at a few of the many ways that bad people try to do bad things to you via email. This first group of scams all fall into the category of Phishing scams. A Phishing scam is basically an email designed to fool you into thinking it is from someone it is not and convince you to click on a link embedded in the email.

The Fake ‘’Account verification’’ Requests

These can seem to come from your bank, Netflix, Twitter, or one of those sites that you don’t admit to having an account on. It doesn’t matter where they are coming from, they all have the same basic message. 

“Your account has been locked for a REASON. To unlock your account before we delete it totally, click on this link.

Here’s a hint, no trusted system out there sends these emails out randomly. If you get one and you are not currently interacting with this organization, then it is almost assuredly a phishing scam.

When in doubt, pull out the paperwork you have for this organization, find a phone number and call them. Ask if there is a problem with your account. When they say no, thank them, wish them a great day, hang up, mark the email as spam, and move on with your life.

The unexpected ‘’Billing error’’ notifications

Did you know that it is possible for bad people to figure things out about you without you telling them? It is relatively simple to find out where a website is hosted. When bad people find out information like this, they like to use it for their gain and your loss. Such is the “Billing Error” notice.  

For instance, if you are a SiteGround customer and you get an email from SiteGround notifying you that there has been a billing error and you now owe $XXXXX more, stop. Don’t click any links in the email. Instead, go to the SiteGround support page and start a chat session with one of their great support people. They can tell you if there’s an issue with your account or not. 

Here’s an example of a phishing email that requests from a SiteGround customer to update their billing details in order to be able to renew their domain:

Scam email example

Notice that this fake email does not contain the name of the recipient, and SiteGround original emails should include the name you’ve used for registering your account. 

Next, notice that this email has grammar and spelling mistakes. These are red flags for a scam email along with the poor formatting. 

Finally, the signature is not the one used by the SiteGround team. 

When you confirm that there is not actually a billing error, thank the nice support person, wish them a wonderful day, disconnect, mark the email as spam, and move on with your life.

The ‘’Order confirmation’’ requests

An oldie but a goodie – and one that pops up a lot these days because ecommerce has exploded – is the “Order Confirmation” email. These are most effective when they are from companies that you’ve never dealt with. They usually involve large sums of money as well. The idea here is to alarm you so much that you will obviously click the link to “Unconfirm” the order. 

If the email looks like it is from a company you don’t do business with, ignore it. Mark it as spam, and move on with your life.

If it looks like it is from a company you do or have done business with, contact them directly outside of the email. Talk with the sales or accounting department and see if someone has placed an order on your behalf… When you find that the answer is no…well, you know the drill by now.

The ‘’Click and collect’’ scam

Thanks to the recent pandemic, “Click and Collect” has become a common way to shop. You buy something online from a nearby retailer. You drive to their store and let them know you are there, they bring the item out to your car. Sometimes, they even put it in your trunk so you don’t have to even meet them face to face.

Nowhere in the Click and Collect workflow is there an email that says “Click here if you didn’t order this.” Treat these the same as Order Confirmation requests. If you don’t deal with the company, it’s a scam. If you deal with the company but haven’t placed an order, it’s a scam. If you are in doubt, contact the company directly, not by replying to the questionable email.

Sometimes, scammers are really REALLY good. They send you an email that looks exactly right.

Real Life Phishing Emails (Well, Screenshots)

What do good phishing emails look like? Here are a few examples of actual phishing scam emails sent to SiteGround customers.

Apart from all the red flags already covered above, the ‘from’ email address of these emails is not a valid SiteGround email. What is more, a proper SiteGround email would never mention the payment method used by you to pay for the service in question.

If you’re a SiteGround customer who comes to report such emails, SiteGround would ask you to send the whole email as an attachment, as they use it to train their own systems to block such emails (in case your email is hosted with SiteGround), so that they do not reach your inbox. In case your email is not hosted with SiteGround, you can mark it as spam in your email provider.

To learn more about how to stay safe from phishing email attacks, check out the blog post on this topic.

How Do You Stay Safe from Email Scams During the Holidays?

So how would you tell if this was a scam email? Well the easy answer is to “practice safe email”. Here are a few of the things I do before I click a link on an email, any email.

  1. Check the ‘from’ address.
    We’ve already done this but so very many phishing emails come from implausible email addresses. Most scammers don’t bother to try and hide it because so few people pay attention. A recent phishing attempt sent to me purported to come from NetFlix. However, the email address was XXX@yahoo.jp. Yes, Yahoo has a Japan domain but they don’t send email for NetFlix from it! Not even to Japanese customers.

    A good rule of thumb is if you were not expecting an email from someone, even a family member or friend, treat it as suspicious until you know it was actually from them. If you don’t recognize the person it came from, then automatically assume it is malicious until you can prove otherwise. 
  2. Check all links before clicking.
    Most email clients these days will let you hover over a link that says “Click Here” (or wherever) and see what the actual URL is. Read it VERY CAREFULLY. Pay attention to the domain name. https://goog.le is not the same as https://google.com. Read it carefully. If it looks suspicious, do not click it.

    Some email programs will show you the link in a popup when you click it and ask for verification before it actually opens a browser to that link. If your email program will do this, by all means turn this feature on. Yes, it adds an extra step before you can see that precious baby picture your friend sent you, but it allows you to make sure that you are actually going to see a baby picture and not install malware on your computer.
  3. Do not automatically download attachments
    Your email program should be set to not automatically download attachments. This means that if you download something from an email, you will have to do it on purpose. If the email doesn’t seem right or fails any of the checks we’ve discussed here, don’t download anything. Even things like Microsoft Word documents which seem innocuous (click here to see the invoice for the service you didn’t order) can do malicious things if you open them. If you weren’t expecting someone to send you an email attachment, don’t open it!
  4. Read The Headers
    Ok, this is for the hardcore email nerds out there but those of us who have been doing this a while can discover a lot by reading the headers that come with every email. These days email programs hide the headers from you but they are there if you want to read them. 
  5. Listen to your gut
    My wife, The lovely and talented Kathy, got an email from our worship pastor one day with the subject line “I love you”. She was good friends with this man and while the subject line confused her, it also piqued her interest. She opened it only to find that there was a malicious script attached to the email. It deleted about ½ of the images we had stored on our home server before I could stop it. Thankfully, I had a backup so there was no loss, other than the hours it took to clean up the mess. Had she simply called him, opened a new email and written him at the address she had in her contacts list, or contacted him in any of a half-dozen other ways, she could have found out that it was not from him but was a scam. Instead of trusting her gut, she opened the email.

Other Black Friday Scams To Be Aware Of

Email is by far the easiest way for bad actors to get unsuspecting people to do bad things. However, there are a couple of other ways.

If you get an email with a link to goog.le, it’s easy enough to spot. However, if you are doing your shopping at https://reallyLongDomainName.com and you misspell it or “fat finger” it (typo), then you might end up at a site that looks exactly like the one you were aiming for.

Bad actors look for common misspellings for profitable domains. They buy them up and put copycat sites up. These are sites that look just like the one you were looking for. They probably even have products and a shopping cart. However, make no mistake, they are scams. When you put in your personal information and credit card number, you are not going to get those purple widgets you ordered that your sister will just love. You won’t get anything but a nasty surprise when your credit card statement arrives.

This is really easy to thwart, if you pay attention.

First, after you arrive at a site, look at the address bar. Is there a little lock next to the domain name?

The little lock means that the domain you are using has a secure certificate and that it is valid. If you don’t have a little lock, or if there is a line through it, that means that either the certificate does not exist, or that it is invalid for that domain. Both of those are really big red flags that you don’t want to do any business on this site or put in any of your personal information.

A SSL certificate isn’t always enough to prove that you are on the right website. Scammers can register sitegroound.com, for example, and install a certificate on it. The certificate just provides encryption in most cases. It’s always a good idea to also double check the URL address, especially when you make payments, create accounts, fill out forms, etc.

Sites impersonating landing or login pages

The final type of website scam we’ll talk about are fake login pages. These might be part of a very good looking fake, or you might arrive at a site only to find that before you can get to the good stuff, you have to enter your login credentials. If this is an ecommerce vendor you normally do business with, or an institution you bank with, stop. Don’t do anything else. Sites like that don’t just put up a login page without letting everyone know well in advance. These are nothing more than “password collectors”. 

If you do enter your credentials into the site, they won’t work…because they are fake. But humans are stubborn. You will assume that you mis-typed something…especially if you are using a long and very secure password. So you’ll try again.

If you are like most of us, when it doesn’t work the second time, you will assume that you’ve used the wrong password and you’ll try another password, and another, and maybe even a 4th one before starting to think that something may be wrong.

Every set of credentials you entered have gone into a database and bad people will start using them to try and sign in to any site they think you may have an account on. Since you were giving them real login credentials, you’ve given away the keys to the kingdom.

Be watchful, be alert, be suspicious bordering on paranoid. Make sure before you put any information into a website, you are absolutely sure you are at the right website. Looks can be deceiving.

How to Practice Safe Internetting This Holiday Season

  1. Always be suspicious of unknown or unexpected emails.
    If you don’t know the person, or even if you do know them but aren’t expecting to hear from them, be suspicious. Yes, your long lost aunt may be contacting you via email with a hotmail.com email address to tell you that she’s leaving you her entire fortune when she dies and she needs you to sign the will, but chances are really good that it might NOT be her. Verify before you take any action.
  2. Don’t click a link in an email until you are absolutely sure you know where it is going and what is going to happen.
  3. Don’t provide your personal information to any site unless you are positive and you know that it is the site you think it is. If you don’t think you are on the right site, close the browser immediately.
  4. Whenever possible, use a Virtual Private Network (VPN) from a reputable provider.
    I won’t name my Internet provider but I will say that I do not trust them. They have been known to make it easy for bad people to watch the traffic going across their network and pull out information as they see it. These days almost all websites use encryption to make sure that’s not easily done, but it is still possible for people with enough time, money, and determination. So whenever possible, I use a VPN to encrypt my traffic even further.

    VPN software isn’t expensive these days, as a matter of fact, if you are a “computer person” you can download, configure, and run your own. I don’t recommend that as it’s easy to get it wrong, but I’ll admit to having done that in the past. These days, I use a commercial VPN that comes with my virus protection. Now, my neighbor can’t see any of my traffic because I’ve got an encrypted tunnel between my network and a server in Miami, FL, USA. (I can choose from about 50)
  5. Don’t use the same password on any 2 websites
    Look, I know how hard this is. It’s difficult to come up with one secure password that you can remember, let alone the 20-30 you need to make sure every site is different. I suggest using a password manager from a reputable software company. There are a few of them out there. The one I use works on Windows, Mac, iOS, iPadOS, and Android. So, no matter where I am at, my passwords are with me. All my passwords on all major sites are long, random, and unique. If you know one of them, you can’t get into anything but that one service I use it for.

Wrap-up

Stay safe out there this holiday season. Have fun, enjoy the company of family, and if you get an email from me saying that Bill Gates is giving 1 Bitcoin to each person that forwards this email…well, you get the idea.

[subscribe_cta]

Journey of an Online Buyer 2022 (Free Guide)

Journey of an Online Buyer Guide

This blog post outlines SiteGround’s Journey of an Online Buyer infographic. Download the full guide to learn about the shifts in customer behavior and how to prepare your website for them. 

With consumers changing the way they shop, have you changed the way you sell? Buyers today are more informed, involved, and connected than ever before. And in today’s digital landscape, the buyer’s journey has taken on new shapes and forms. It is no longer a linear process but a complicated web of touchpoints and interactions. To keep ahead of the competition as a small business and website owner, it’s critical to grasp this new buyer’s journey online.

What is the buyer’s journey?

The buyer’s journey is the process consumers go through, from initial awareness to final purchase. It illustrates how each step leads to the next to ensure you are aware of the actions that cause potential clients to either make a purchase, or back out of it. By understanding the buyer’s journey, you can better anticipate the needs of your customers and provide them with a seamless experience from start to finish.

The three stages of the buyer’s journey

It’s up to you to observe how potential buyers react to your selling approach and determine precisely where to focus your marketing and sales efforts. The buyer’s journey is mapped out in three stages. Each stage allows for distinct interactions between you and your users. 

Awareness stage

During the awareness stage, the buyer becomes aware of a problem or challenge they face. They will then begin to search for solutions to that problem. Your job during this stage is to make sure you are visible to the buyer and that they are aware of your product as a solution to their problem.

Consideration stage

The consideration stage is when the buyer narrows their options and compares different solutions. Usually, this happens on your website. During this phase, it is your responsibility to give the customer the best user experience possible, which entails having a fast and secure website. Also, give them more information about your product and how it compares to competing products.

Decision stage

The decision stage is when the buyer finally chooses a solution. Your job during this stage is to make the purchase process as easy as possible and address any final buyer concerns.

Your website’s role in the buyer’s journey

While the buyer’s journey may start elsewhere, such as with a Google search, a large part of it will happen on your website. This is why it’s essential to have a website optimized for SEO that provides a great user experience, including ultrafast website speed, security, and reliability. If you can do this, you’ll be able to guide the buyer through the journey and ultimately convert them into a customer.

The 2022 online buyer’s journey highlights

Online shopping has evolved beyond simply being more convenient

Online shopping has come a long way since its inception. What started out as a convenient way to search for items has evolved into a major part of the retail landscape. Consumers around the world were once skeptical about online shopping, but that has changed dramatically over time – especially after the pandemic. Statista reports that in 2021, retail ecommerce sales were 5.2 trillion US dollars globally. They estimate this number will grow 56% in the next years, amounting to 8.1 trillion by 2026.

Seasonal shopping now starts much earlier 

In the past, people would wait until the last minute to do their holiday shopping. However, people now do their seasonal shopping much earlier. They have many more options to choose from online, and want to take their time to find the perfect purchase. This is due to several factors, one of which is the growth of online shopping. With the shopping season starting earlier and earlier each year, small business owners need to be prepared to accommodate early shoppers.

As advertising costs soar, brands prioritize building customer lifetime value

Building customer lifetime value is more important than ever. As advertising costs rise, brands are increasingly focused on creating long-term relationships with their customers. And that’s okay because we’re also seeing a shift in the way consumers choose from whom to buy. They’re much more likely now to purchase from companies with strong brands that identify with their consumers. It’s important to remember that sustainable growth comes from focusing on your customers. So you need to build a brand that customers can trust and foster a sense of community. 

Download the full guide below to explore the changes in customer behavior and learn how to get your website visitors a step closer to the “buy” button on every step of their online journey.

>> DOWNLOAD THE FULL GUIDE 

[subscribe_cta]