Web Design & Dev · News

June 2026 — Web Design & Dev news.

June 2026

What changed, as it happens.

Tracked daily from primary sources. The items below are what we're watching for clients right now.

  1. Bots · Analytics

    Microsoft Clarity now flags bots that ignore your robots.txt

    Clarity added a robots.txt-violations layer to its Bot Analytics dashboard, showing which crawlers request disallowed URLs, trends over time, and filtering by operator — practical visibility into AI crawlers like ClaudeBot and GPTBot ignoring directives. It needs a connected CDN or the latest Clarity WordPress plugin.Source: Search Engine Journal →

    Our take: Free visibility into which AI crawlers ignore your directives — worth enabling just to know. Pairs with the Cloudflare edge-blocking deadline in our SEO feed: learn who actually crawls you before deciding who's allowed to.

    Read our full take →
  2. AI Agents · Standards

    Google and Shopify back Cloudflare’s PACT protocol for gating AI bots

    Google, Shopify, and several browser makers are backing PACT, a Cloudflare-hosted standard for authenticating and gating AI agents and automated bots. It’s positioned as a permission and authentication layer for agentic web access, complementing the ARD and WebMCP specs — and Shopify’s support signals ecommerce platforms are wiring these standards into their infrastructure.Source: Search Engine Journal →

    Our take: Standards backed by both Google and Shopify tend to become defaults. This is the permission layer your future agent traffic will negotiate with, and it will likely surface as a Cloudflare toggle you should set deliberately, not inherit.

    Read our full take →
  3. Agentic Web · Chrome

    Chrome ships a Lighthouse “Agentic Browsing” audit in M150

    Chrome shipped an informational Lighthouse “Agentic Browsing” audit category in M150 that checks accessibility-tree quality, Cumulative Layout Shift, and WebMCP tool/schema availability. It ships with Chrome DevTools for Agents, which lets developers simulate agent interactions while debugging — early tooling for making sites agent-ready.Source: Chrome for Developers →

    Our take: Run it once on your store: Chrome 150+, Lighthouse, Agentic Browsing category. It's informational, but it's Google telling you what agents need from your site. Accessibility-tree quality does double duty for screen readers and shopping agents.

    Read our full take →
  4. Auth · Security

    Sign in with Google adds session metadata for risk-based access control

    Google added two OIDC claims — auth_time (when the user logged in) and amr (how they authenticated) — to Sign in with Google. Verified apps can use them for step-up authentication on sensitive actions and stronger fraud prevention.Source: Google Developers Blog →

    Our take: If your store offers Google sign-in, the new session claims enable step-up authentication on sensitive actions — address changes, saved-payment edits — without adding login friction everywhere else. Targeted security beats blanket friction.

    Read our full take →
  5. WordPress · Security

    MonsterInsights site compromised and sending phishing emails

    The website of MonsterInsights, a widely used WordPress Google Analytics plugin, was compromised and taken offline, with the company warning of fraudulent emails sent from its domain. It’s a phishing campaign against plugin users, not a disclosed flaw in the plugin — don’t act on unexpected emails from the brand.Source: Search Engine Journal →

    Our take: If your team touches WordPress anywhere — blog, landing pages — warn them now: unexpected MonsterInsights emails are hostile until proven otherwise. There's no plugin flaw to patch; the attack surface is the inbox.

    Read our full take →
  6. WordPress · Security

    UpdraftPlus flaw exposes 3M+ WordPress sites to takeover — patch now

    An authentication bypass in UpdraftPlus WP Backup & Migration (≤1.26.4) lets unauthenticated attackers run admin-level commands and install malicious plugins; Wordfence blocked 8,000+ attacks in 24 hours. Update to 1.26.5 immediately.Source: Search Engine Journal →

    Our take: Any WordPress property running UpdraftPlus 1.26.4 or older gets updated today — this is unauthenticated admin-level takeover with active exploitation. Then ask when your supporting WordPress sites last had a real plugin audit.

    Read our full take →
All Web Design & Dev news

Custom ecommerce software, AI apps, and SEO — the work other agencies quote around, built in-house.

20+ years of BigCommerce engineering, now AI-augmented. Tell us your store, your stack, and your deadline — we quote fixed scope on the first call.