The WordPress security brief for people who actually run WordPress sites.
Disclosures we’ve tracked, procedures we’ve tested, incidents we’ve cleaned up after. Most WordPress security writing online comes from companies selling plugins. Ours doesn’t.
Four desks, one newsroom. WordPress security as reporting, not content marketing.
Four desks. Each owns a different piece of the WordPress security picture, and each publishes at its own pace.
Hardening
File permissions, authentication, database config, WAF rules, XML-RPC, REST endpoints. If we write it, we’ve run it on a real install.
News
Disclosures, campaigns, plugin deprecations, vendor moves. What the WordPress security beat looks like when nobody’s selling you anything.
Incident
Your site is hacked. What happens next. We publish full incident timelines: how we found it, what the attacker did, how we rebuilt.
Reviews
We run the main security plugins against live attack traffic on our own test installs. Rankings move when a product does, not when a press release lands.
Recent research.
A selection from the desks. Longer pieces, with evidence.
The Essential Plugin backdoor: how 31 WordPress plugins went malicious in eight hours
Sold on Flippa, dormant for eight months, activated April 6. The deserialization gadget, the Ethereum C2, and what to do if you were running any of the 31 affected plugins.
The fifteen-minute WordPress security checklist we follow
Eight steps in a specific order. The ones that close the attack surface real scanners actually touch. Commands and config, not feature talk.
WordPress malware removal: the procedure we run on client sites
Identify, clean, close the door, verify. The recently-modified-file diff, the IOCs we actually look for, and why the reinfection arrives forty-eight hours later.
Best WordPress security plugins, adjusted for reality
Five plugins tested on live installs against real attack traffic and a credential-stuffing pool of 120,000 pairs. Where each one wins and where it does not.
WordPress malware protection: the four layers that actually work
Edge, scanner, patching, cleanup. The four defensive layers, the tradeoffs at each, and the plugin stack we actually install on sites at three budget tiers.
How to fix a hacked WordPress site: the first-hour playbook
The decisions before the cleanup. Evidence preservation, containment, three realistic paths out of the compromise, and what to tell your host, users, and Google.
The WordPress pharma hack: cleanup, then the real work
Cleanup is thirty percent of the job. The rest is reclaiming your search presence after Google has indexed thousands of spam URLs under your domain. The SEO recovery arc nobody writes about.
WordPress DDoS protection: target, weapon, and what stops both
Your site is not only a DDoS target. It is a DDoS weapon too. XMLRPC amplification, pingback reflection, origin-IP leakage, and the edge + rate-limit stack that closes all three.
The Plausible Analytics speed module: how a performance shortcut could switch off your firewall
A speed feature unloads every other plugin on proxy requests, gated by a value printed on every page. The bypass we found, the WAF it switched off, and the 2.5.8 fix.
Protect the Shire and the two threats one update button cannot both solve
WordPress.org now holds every plugin update for review, security fixes included. Why one hold cannot answer both the supply-chain threat and the race to patch.
Plugin reviews, adjusted for reality.
We run Wordfence, Patchstack, MalCare, Sucuri and the rest on live installs under real attack traffic. The rankings you find everywhere else are vendor scorecards. Ours moves when a product does.
Read the current roundup