Google confirmed nothing this week — and rankings moved twice anyway. Between 12 and 18 January the SEO tools recorded two separate volatility spikes, Firefox shipped a security-heavy release on the 13th, Chrome pushed version 145 to beta on the 14th with genuinely useful CSS features, Google folded Gemini into Trends, and a CVSS 10.0 WordPress plugin flaw started getting exploited in the wild. If your website is how customers find and choose you, here's what actually happened this week — and what each item means for a business site that has to earn revenue, not just exist.
1. Unconfirmed volatility, twice: 12 January and 15–16 January
What happened
Rank-tracking tools lit up around Monday 12 January, then again on Thursday–Friday 15–16 January, with site owners reporting ranking and traffic swings on both dates. Google announced nothing. That makes three unconfirmed tremors in a fortnight — one hit on 6 January too — and the pattern follows straight on from the December 2025 core update, which finished rolling out on 29 December. Some webmasters on the forums reported traffic drops as steep as 90% week over week; others saw recoveries just as sharp a few days later.
How to read back-to-back unconfirmed spikes
- Two spikes in one week usually means testing, not a launch. When Google trials ranking changes, tools see waves that partially reverse. Compare your positions on the 12th, 15th and 18th before concluding anything.
- Separate rankings from clicks. A position drop and a click drop have different causes. Post-core-update turbulence often shifts clicks (via SERP feature changes) more than positions.
- Benchmark against competitors. If your whole niche moved on the same dates, it's the algorithm breathing. If only you moved, audit what changed on your site since mid-December.
- Rule out the boring causes first. An expired plugin, a slow deploy, a broken redirect — mundane failures explain more "algorithm hits" than algorithms do.
Log the dates, hold the line, and resist the panic rewrite. Sites that get knocked around by every unconfirmed tremor almost always share the same profile: thin structure, slow pages, borrowed content. That's a build problem before it's a content problem — and it's the first thing we audit as a website development company when a client arrives mid-volatility.
2. Firefox 147 ships with 16 security fixes and WebGPU on Apple Silicon
Mozilla released Firefox 147 on Tuesday 13 January, patching 16 security vulnerabilities — six of them high-impact, including multiple sandbox escapes that could enable arbitrary code execution. Beyond security, the release enables WebGPU on Apple Silicon Macs, adds compression dictionary support for smaller repeat downloads, improves picture-in-picture, and — for the Linux faithful — finally adopts the XDG base directory spec after twenty years.
Why a browser release is a business-website story
- Test your site in it. Firefox is a minority browser but a vocal one; rendering bugs there still cost real conversions, especially on checkout and form flows.
- WebGPU is now two-browser territory on Mac. If you've held off on WebGPU-powered product visualisers or 3D configurators because of Safari-and-Chrome-only support, the calculus just improved.
- Compression dictionaries reward clean asset pipelines. Returning visitors download only what changed — but only if your build produces stable, cacheable bundles.
3. Chrome 145 hits beta: text-justify, multicol wrapping and JPEG-XL
On Wednesday 14 January, Google promoted Chrome 145 to beta for Windows, Mac and Linux, with stable expected in early February. For people who build websites for a living, this one is unusually meaty:
- The text-justify CSS property arrives, giving designers real control over justification behaviour — long a print-design capability the web faked badly.
- Column wrapping in multi-column layout lands, making magazine-style multicol genuinely usable in responsive contexts.
- JPEG-XL decoding returns to Blink — a modern image format with better compression than JPEG at equal quality, back from the dead after Google removed it in 2022.
- An SQLite backend for IndexedDB and reduced user-agent strings by default round out the platform changes, along with more granular permissions for sites requesting local network access.
Two action items before February's stable release: audit any analytics, personalisation or serving logic that parses user-agent strings — reduced UA strings will quietly break naive detection — and get JPEG-XL into your image pipeline evaluation next to AVIF and WebP. Both are classic html web development chores: invisible when done right, expensive when skipped. Faster images and unbroken detection feed directly into conversion optimization, because every 100ms of image weight you shed shows up in bounce and checkout rates.
4. Google folds Gemini into Trends and keeps tweaking the AI search box
Also on 14 January, Google announced that Google Trends now uses Gemini to automatically identify and compare relevant trends for a topic — turning a manual compare-five-terms workflow into an AI-assisted one. The same day, testers spotted Google experimenting with the AI Mode entry point in the search box, where the AI Mode option disappears as you type and is replaced by a plain blue Send button. Small tweak, big signal: Google is still iterating on how prominently AI answers sit in the default search journey.
What this means for keyword and demand research
- Gemini-assisted Trends speeds up discovery, not validation. Use it to surface adjacent demand you hadn't considered, then validate against Search Console queries and actual conversion data before building pages.
- The AI search interface is not settled. Every UI experiment shifts how much traffic classic blue links receive. Watch your click-through rates around these test windows rather than assuming stable baselines.
- Seasonal planning gets cheaper. For ecommerce especially, AI-compared trend lines make it faster to time category pages and campaign landing pages to demand curves.
5. WordPress: a CVSS 10.0 exploit in the wild, and the road to 7.0
Two WordPress stories this week, one urgent and one strategic. The urgent one: a critical CVSS 10.0 vulnerability in the Modular DS Connector plugin — allowing unauthenticated attackers to create administrator accounts — began being actively exploited in the wild in mid-January. If that plugin is anywhere in your stack, patch or remove it today and audit your admin user list for accounts you didn't create.
The strategic one: WordPress 7.0 planning moved forward, with the release targeted for 9 April at WordCamp Asia, the call for release-squad contributors circulating, and Gutenberg 22.3 landing early 7.0 features — including a new Fonts screen and PHP-only blocks. Real-time collaborative editing remains the headline ambition for the 7.0 cycle.
The exploit is the story. Most hacked business sites we're brought in to rescue weren't targeted — they were running one unpatched plugin among forty. Keep a plugin inventory, remove anything unused, and put updates on a weekly schedule with backups before each run. If nobody owns that job at your company, that's the real vulnerability.
What this week means for your website strategy
Pull the five stories together and a clear brief emerges for anyone scoping web design or development work in 2026:
- Volatility resilience is a build-quality feature. Three unconfirmed spikes in two weeks is the new normal. The sites that shrug them off are fast, well-structured and genuinely expert — qualities decided at build time, not bolted on after.
- The browser platform is moving fast in your favour. text-justify, multicol wrapping, JPEG-XL, WebGPU on more hardware — the design ceiling keeps rising for teams that actually track releases. Ask any agency you're evaluating what shipped in Chrome 145; the answer tells you whether they build for the platform or from templates.
- Maintenance is not optional. A CVSS 10.0 exploit doesn't care how good your branding is. Whether you're on WordPress or Shopify, someone must own patching. It's a question worth putting to Shopify development partners and WordPress agencies alike before you sign: who watches the vulnerabilities after launch?
And on ecommerce specifically: a Shopify developer partner worth hiring should be able to explain how this week's image-format and UA-string changes affect theme performance. If the answer is a blank look, keep interviewing.
Frequently asked questions
Was there a Google algorithm update the week of 12 January 2026?
Nothing confirmed. Rank-tracking tools recorded two unconfirmed volatility spikes — around 12 January and again on 15–16 January — following a similar tremor on 6 January. Google announced nothing, so treat the swings as background volatility after the December 2025 core update rather than a named update to react to.
Should I update to Firefox 147, and does it matter for my website?
Yes — Firefox 147 shipped 13 January 2026 with fixes for 16 security vulnerabilities, including six high-impact flaws. For site owners it also enables WebGPU on Apple Silicon Macs and compression dictionary support, so test your site in it, especially anything using canvas, video or heavy graphics.
What is new for CSS in Chrome 145?
Chrome 145 entered beta on 14 January 2026 with support for the text-justify property, column wrapping in multi-column layout, JPEG-XL image decoding, an SQLite backend for IndexedDB and reduced user-agent strings by default. It reaches stable in early February, so audit any code that parses user-agent strings now.
Is the WordPress plugin vulnerability from mid-January 2026 serious?
Yes. A CVSS 10.0 flaw in the Modular DS Connector plugin let unauthenticated attackers create administrator accounts and was actively exploited starting mid-January. If you run the plugin, update or remove it immediately and audit your admin user list. Even if you don't, it is a reminder to inventory and patch plugins on a schedule.
How does Gemini in Google Trends change keyword research?
As of 14 January 2026, Google Trends uses Gemini to automatically identify and compare relevant trends for a topic. It speeds up demand discovery, but the output is a starting point — validate anything it surfaces against Search Console query data and actual conversion behaviour before building pages around it.
The takeaway
A week with no confirmed Google update still managed to move rankings twice, ship two browser releases' worth of platform change, and put a maximum-severity exploit into active circulation. The lesson isn't to chase each item — it's that websites now live in permanent motion, and the ones that keep winning are maintained like products, not launched like brochures. Whether you search "web developers near me" or hire across an ocean, that's the standard to hold any partner to: does the work move revenue for a business website, week after week, in conditions exactly like these?
Sources & further reading
- Search Engine Roundtable — Google Search Ranking Volatility Around January 15–16
- Mozilla — Firefox 147.0 Release Notes (13 January 2026)
- Chrome for Developers — Chrome 145 beta (14 January 2026)
- Search Engine Roundtable — January 2026 Google Webmaster Report
- WordPress.org — Proposal: 2026 Major Release Schedule
- Impression — January 2026 Google algorithm and search industry updates