The publication.
WP Spear is an independent WordPress security publication. We are not a plugin vendor’s blog, not a content farm, not a security-as-a-service provider. We test products on our own infrastructure, report what we find, and publish the methodology alongside the conclusions. The goal is simple: be the source a WordPress operator can trust when they need to make a security decision and do not have the time to run the tests themselves.
What this is. What this is not.
Most WordPress security writing online is published by companies that sell WordPress security. The incentives are visible in every sentence. We built this publication to be the alternative. One that ranks products on technical merit, covers incidents without spin, and writes for operators rather than prospects.
Independent editorial
No vendor owns us. No investor dictates coverage. Rankings move when products do, not when a press release lands. Affiliate revenue supports the work but does not shape it.
Tested on live installs
Every plugin review runs for ~6 weeks on isolated infrastructure against real attack traffic: credential stuffing pools, deliberate malware injections, WAF bypass attempts. We report what happens, not what the marketing says.
Plain language
No hedging, no vendor-speak, no AI-generated filler. If we are not sure about something, we say so. If a product is bad, we say that too. Writing is audited against a specific anti-pattern list before publication.
Source trail
Every factual claim points back to where we verified it. News pieces explicitly list sources. Reviews document the test rig. If you want to second-guess a conclusion, we give you the material to do it.
Deliberate cadence
Some pieces take six weeks of testing. Some take an afternoon to report. We publish when the work is done, not when the editorial calendar calls for it. Quality over velocity.
Open correction
If we get something wrong, we correct it and say what changed. Revision trails matter more than pretending to be infallible. Send corrections to the tips address and we will act on them.
Affiliate policy, in plain terms.
The business model is transparent because obscuring it would undermine the editorial claim. Here is what you need to know.
Affiliate links are disclosed per article, not buried in a footer
Every review that contains affiliate links opens with a plain-language disclosure. Links marked with rel="sponsored" and visible call-outs in the piece. No dark patterns.
Rankings are not for sale
We have given mid-tier ratings to products whose affiliate programs we participate in, and high ratings to free tools with no affiliate revenue. The rating model is published. The evidence is cited. If the ranking changes we say why.
No sponsored content
No paid placements, no “partner spotlights”, no vendor-authored guest posts framed as editorial. Every piece published here is written by the WP Spear team on our own schedule, for our own editorial reasons.
No Google tracking on reader behaviour
We do not run Google Analytics. We do not run any third-party analytics. We look at server logs occasionally when something breaks. Reader privacy is the default, not a premium feature.
Who writes this.
WP Spear publishes under a single editorial byline. The team includes WordPress security researchers, incident responders, and site administrators with experience across enterprise and small-business WordPress environments. The byline is intentional, not evasive.
The publication is the author, not the individual
Readers should trust the editorial standard, not the name of the person who happened to draft a particular piece. A single byline makes the publication accountable for its whole output rather than letting any one contributor accumulate outsized authority. It is also how most serious trade publications have worked since the 1890s.
Guest research and post-mortem contributors
If a guest researcher contributes to a technical post-mortem or a named expert consents to be quoted, they get a named byline on that specific piece. Otherwise every pillar, review, and news brief is published under the WP Spear team byline.
Published since Q3 2017
The publication has been operating under variations of this editorial standard since its founding. Some pieces in our archive have been revised to match current standards. The masthead, the voice, and the editorial position have stayed intentionally consistent across the years.
Get in touch.
We accept tips on active incidents, responsible-disclosure vulnerability reports, story pitches, and corrections. We do not accept sponsored placements or pay-to-review requests. Please read the category below before reaching out.
[email protected]
Active WordPress compromises, plugin-level disclosures, supply-chain anomalies, or anything on the security beat we should be reporting on. Include technical detail; we verify before we publish.
[email protected]
Security issues in wpspear.com itself. PGP available on request. Coordinated disclosure preferred; we commit to acknowledging reports within 48 hours and patching verified issues before publication.
[email protected]
Story pitches, corrections, product-review requests, press inquiries, permissions to quote. Replies typically within a business week. Pay-to-review requests are declined; please do not waste either party’s time.