Installing Theme Updates
As of today we’re stripping out the update mechanism that updates your MeanThemes theme from within WordPress.
Well the answer is three-fold. Firstly, the third party plugin we used is now a couple of years old and isn’t maintained by the plugin author. Secondly, the download links are open for anyone to see if they dig through the code enough, meaning that if someone is savvy enough they can work out how to get all of our themes for free. We thought this was an acceptable risk when we had a few themes out. We’ve been monitoring traffic to the theme files on the update server recently and we’re getting far more hits than we should be to those files which could indicate that some naughty pirates are stealing our themes. Thirdly, as of today a XSS vulnerability was revealed that is present in the update mechanism which is unlikely to get patched as the plugin is unmaintained.
So how do you update?
Well, it’s pretty simple actually…
You can use the Envato Toolkit WordPress Plugin.
And then follow this handy guide on how to set it all up.
What about non-ThemeForest themes?
Check the changelogs regularly if you bought from Etsy. Creative Market has an update notification, you only need to unzip the main package first and upload what is in the “Theme” folder.
Then login to your WordPress install, activate another theme. Delete the MeanThemes theme. Then upload the new version you just downloaded from your chosen marketplace and activate. Job done.
When is this all going to happen?
We’ll be rolling out updates over the next few days addressing the XSS issues and stripping out the mechanism for updating within WordPress.
Don’t forget to sign up to our newsletter to receive more important information like this along with new theme releases.