What Is New With Website Maintenance in August 2026? Latest release notes and search documentation and Key Takeaways

Use this August checklist to patch WordPress, test browser-side media handling, audit favicons, and review regional policy exposure.

Website maintenance in August 2026 centers on WordPress 7.1, an urgent WordPress security fix, and Google documentation changes involving favicons, Preferred Sources, and site reputation enforcement. The key takeaway is to update WordPress first, then test media workflows and audit search-facing assets and policy exposure. Website maintenance means keeping a site secure, functional, compatible, and accurately represented in search. This month's changes affect site operators, developers, publishers, and teams responsible for regional search performance.

Table of Contents

What changes with WordPress 7.1?

wordpress released version 7.1 on august 19 with responsive styling controls, a redesigned media editor, and expanded collaboration features. The WordPress 7.1 release announcement also describes a substantial change to image processing. Compression, resizing, and thumbnail generation now happen in the browser.

This reduces server load and helps sites avoid PHP memory limits and upload timeouts. WordPress 7.1 also adds native support for AVIF, HEIC, and HDR gain-map images. Teams should test the release against representative content rather than checking only whether the dashboard loads:.

  • Upload typical large images and verify the resulting sizes and thumbnails.
  • Test AVIF, HEIC, or HDR gain-map files used by your publishing workflow.
  • Check responsive styling at the screen sizes your layouts target.
  • Confirm that existing editorial and collaboration routines still work.

Which WordPress update is urgent?

WordPress 7.0.4 fixes an authenticated remote-code-execution vulnerability involving malicious file uploads on sites using Imagick and Ghostscript. The issue applies at the Author level and above, and the WordPress security release recommends updating immediately. "Authenticated" means the attack requires a valid account with sufficient permissions. Remote code execution means an attacker can cause code to run on the server.

The authentication requirement narrows the risk, but it does not make the flaw safe to postpone. WordPress also said only its newest version is actively supported. Although work began to backport the fix as far as the 4.7 branch, maintainers should not treat an older patched branch as equivalent to active support. update the affected installation, then plan a move to the current release if the site remains on an older branch.

Did Google add new favicon formats?

google's August 28 favicon update clarified existing format support rather than introducing new support. The documented formats are BMP, GIF, ICO, PNG, JPEG, PPM, and TIFF, according to the updated Google Search Central favicon documentation.

A valid format alone is insufficient. Google says the favicon must be crawlable by Googlebot and Googlebot-Image, and it does not guarantee that a compliant favicon will appear in search results. A focused favicon audit should therefore:.

  • Confirm that the favicon uses a listed format.
  • Verify that both required crawlers can access the file.
  • Check that crawler restrictions do not block the favicon URL.
  • Avoid promising stakeholders that technical compliance guarantees display.

What can eligible publishers do with Preferred Sources?

Google updated its Preferred Sources guide on August 20. Eligible publishers can add a localized interactive "Preferred Sources" button or a deeplink that lets readers select the publication. A selected publisher becomes more likely to appear in Top Stories.

"More likely" is an important limit: the feature improves the opportunity for visibility but does not promise placement. Eligible publishers should choose the implementation that fits their available page space, localize it for their audience, and test the complete selection path. Publishers that are not eligible should not schedule development work around the feature.

How does regional policy enforcement differ?

Beginning August 30, Google changed how it enforces its site reputation policy for searches in the European Economic Area. Outside the EEA, a manual action directly affects the offending section; inside the EEA, that section may instead be separated and rank independently over time, according to Google's site reputation policy update. This distinction can produce different outcomes for the same section across regions.

Site owners assessing a manual action should avoid relying on one worldwide visibility report. Identify sections that may fall under the policy, separate EEA and non-EEA reporting, and document when changes occur. From August 30 onward, comparing the two regions separately can reveal enforcement effects that a global report would hide.


You Might Also Like