Skip to content

Add Update URI: false to generated themes to prevent WordPress.org slug collisions #875

Description

@thetwopct

Description

Themes created by Create Block Theme can be silently overwritten by an unrelated theme from the WordPress.org Theme Directory when both themes have the same slug.

This came up during a Create Block Theme workshop. A participant cloned the Bluehost Blueprint theme and named the clone Cozy Cafe. Create Block Theme generated the slug cozy-cafe and activated the new theme successfully. A different theme already exists in the WordPress.org Theme Directory with that slug. WordPress subsequently treated the workshop participant's custom theme as the directory theme and replaced it with the unrelated Cozy Cafe theme during an update.

From the participant's perspective, the theme they had just created suddenly changed into a completely different theme, with no indication that choosing the name could put their work at risk.

WordPress 6.1 introduced the Update URI theme header specifically to prevent custom themes from being overwritten when their slug happens to match a WordPress.org theme:

https://make.wordpress.org/core/2022/10/06/introducing-update-uri-theme-header-in-wordpress-6-1/

Steps to reproduce

  1. Activate a block theme, such as Bluehost Blueprint.
  2. Use Create Block Theme to clone it.
  3. Name the new theme Cozy Cafe.
  4. Confirm that the generated theme directory and text domain are cozy-cafe.
  5. Allow WordPress or the hosting provider to check for and apply theme updates.

Actual result

WordPress detects the unrelated cozy-cafe theme from WordPress.org as an update. Applying that update replaces the custom theme's files and can destroy the user's work.

The local file_exists() check only protects against an existing directory at creation time. It does not protect the generated theme from a later WordPress.org update.

Expected result

Every newly created theme produced by Create Block Theme should be protected from unrelated WordPress.org updates by default.

Proposed solution

Add the following header to every newly generated clone, blank theme, and child theme:

Update URI: false

This should apply to themes newly created by CBT. Existing Update URI values on source or existing themes should be preserved when CBT saves, edits, or exports them, so intentional third-party update integrations are not disabled.

An additional warning when a generated slug already exists in the WordPress.org Theme Directory could be useful, but the generated Update URI: false header should provide the underlying protection even when a collision appears later.

Environment

  • Create Block Theme 2.10.1/current trunk
  • WordPress 6.8 or later

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions