Resources · Design

Guides on ecommerce design and conversion for BigCommerce stores.

Articles on product page design, checkout UX, conversion rate optimization, and Lighthouse performance for BigCommerce Stencil themes.

Latest industry news

What changed, as it happens.

Tracked daily from primary sources. The items below are what we're watching for clients right now.

  1. WordPress · Security

    WordPress patches a login-screen flaw that needs no account to reach

    WordPress 7.0.3 fixes twelve vulnerabilities, including stored XSS in several blocks, server-side request forgery, privilege escalation on multisite networks and information disclosure. The most severe is a cross-site scripting issue on the login screen, scored 8.9 and reachable without authentication; WordPress's security repository states it can be escalated to remote code execution under conditions outside the attacker's control, requiring successful social engineering of the target and explicit interaction from them. Fixes are backported to WordPress 4.7 and later, and sites with automatic updates enabled are receiving them. Researchers from Anthropic, pwn_ai and Aikido Security were among those credited.Source: Search Engine Journal →

    Our take: Minor releases install themselves on most WordPress sites and this one backports to 4.7, so the patch is probably already on. Most owners have not checked. Auto-updates get switched off during a migration or a plugin conflict and rarely get switched back on, and an 8.9 on the login screen with no account required is a bad one to find out you missed. The escalation path needs the victim to click, a condition that holds until someone builds a convincing enough page.

    Read our full take →
  2. WordPress · Accessibility

    WordPress 7.1 rewrites the admin list tables, and some plugins will notice

    WordPress 7.1, scheduled for release on 19 August 2026, changes the HTML structure of admin post list tables to fix an accessibility bug that has been open for eleven years. Screen readers currently announce each row using the checkbox column header, "Select All", rather than the post title. In 7.1 the checkbox column moves from a th to a td, the post-title column becomes a th with scope="row" and carries an aria-label holding the post title, and collapsed cells in the responsive view move to a flex layout. Search Engine Journal reports the code at risk is plugins using CSS or JavaScript selectors that target specific th or td elements in those tables, and that public-facing site functionality should be unaffected.Source: Search Engine Journal →

    Our take: This one sorts itself by stack. A BigCommerce or Shopify storefront has no WordPress admin to break, and where WordPress runs the blog the damage is confined to a screen customers never see. Eleven years is a long time for a screen reader to have been reading "Select All" in place of every post title.

    Read our full take →
  3. WordPress · Security

    A forged Apple login token takes over any WordPress site running WooCommerce Social Login

    CVE-2026-8457 is a critical authentication-bypass vulnerability in the WooCommerce Social Login plugin, affecting versions up to and including 2.8.7 and fixed in 2.8.8. It scores 9.8 out of 10 on CVSS. The plugin's Apple login handler does not validate Apple's JWT identity tokens against Apple's public keys, so an attacker can forge a token carrying any email address and be signed in as the matching user. Wordfence describes the result as unauthenticated attackers being able to log in as any existing WordPress user, including administrators. Administrator accounts carry no exclusion protection here, so a successful attempt hands over full control of the site without any legitimate credentials.Source: Search Engine Journal →

    Our take: Update to 2.8.8 today if this plugin is installed anywhere you touch. A 9.8 with a forged-token path and no credentials required is the class that gets scanned for within days of disclosure, and social login is the kind of plugin switched on once during a launch and never opened again. For most BigCommerce and Shopify merchants the exposure sits on the WordPress blog or landing-page install on a subdomain beside the store, where the plugin list has not been read in a year and an administrator account is one forged token away.

    Read our full take →
  4. CSS · Layout

    CSS border-shape takes shaped elements past what border-radius can do

    CSS-Tricks published an explainer on border-shape, a CSS Borders Module Level 4 property that accepts the same values as clip-path — including the newer shape() function — but shapes the whole element rather than clipping it. That distinction is the point: borders, box-shadows, and outlines follow the shaped path instead of being cut off at it, which makes putting a real border on a non-rectangular CSS shape straightforward for the first time. Support is Chrome-only as of July 2026, so treat it as something to explore rather than ship.Source: CSS-Tricks →

    Our take: Chrome-only means explore, don't ship. For stores it's eventual relief from the SVG-mask gymnastics behind badge shapes and promo callouts, a progressive-enhancement candidate for late 2026, not a today tool.

    Read our full take →
  5. AI Tooling · Design Systems

    NN/G floats a “UX.md” — machine-readable context for AI-generated design

    Nielsen Norman Group argues UX work should shift toward curating machine-readable context that AI tools consume when they generate design, rather than producing human-only deliverables like personas and reports. The anchor is real: Google Labs open-sourced DESIGN.md in April 2026, a file that lives alongside a product’s code and pairs machine-readable values — colors, type sizes, spacing — with human-readable guidance so a tool knows what a color is actually for. “UX.md” itself is NN/G’s thought experiment, not a standard anyone implements yet. Worth reading as a direction, not a checklist.Source: Nielsen Norman Group →

    Our take: The direction is real even if UX.md isn't a standard yet: machine-readable design context is how AI-generated pages stay on-brand. We keep exactly that, tokens plus intent, in this site's repo; it's why AI-assisted edits don't drift the palette.

    Read our full take →
All Web Design & Dev news
Web Design & Dev

Guides, fundamentals & FAQ

Deep dives, explainers, and the questions clients ask most.

Product detail pages

PDP Design Anatomy

The elements that drive add-to-cart on a product detail page — hero image, variant selector, trust signals, CTA placement, and the mobile-first considerations most desktop-first designers miss.

Design service →
New · July 2026

Stencil Performance: Lighthouse 95+

Where BigCommerce storefronts actually lose speed — app scripts, hero images, carousels, fonts — and the Stencil-specific fixes that get Core Web Vitals to Good and Lighthouse past 95.

Read the guide →
Reducing cart abandonment

Checkout UX for BigCommerce

BC's hosted checkout vs. custom checkout SDK — what you can and can't customize, the UX decisions that reduce abandonment, and B2B-specific checkout flows (PO number, NET terms, quote approval).

Development service →
Conversion rate optimization

CRO for Ecommerce

How we approach conversion rate optimization on BigCommerce stores — heatmaps, session recordings, funnel drop-off analysis, and the high-leverage changes that move conversion without a full redesign.

Design & redesign service →

Custom ecommerce software, AI apps, and SEO — the work other agencies quote around, built in-house.

20+ years of BigCommerce engineering, now AI-augmented. Tell us your store, your stack, and your deadline — we quote fixed scope on the first call.