About

The publication.

WP Spear is an independent WordPress security publication. We are not a plugin vendor’s blog, not a content farm, not a security-as-a-service provider. We test products on our own infrastructure, report what we find, and publish the methodology alongside the conclusions. The goal is simple: be the source a WordPress operator can trust when they need to make a security decision and do not have the time to run the tests themselves.

What this is. What this is not.

Most WordPress security writing online is published by companies that sell WordPress security. The incentives are visible in every sentence. We built this publication to be the alternative. One that ranks products on technical merit, covers incidents without spin, and writes for operators rather than prospects.

01

Independent editorial

No vendor owns us. No investor dictates coverage. Rankings move when products do, not when a press release lands. Affiliate revenue supports the work but does not shape it.

02

Tested on live installs

Every plugin review runs for ~6 weeks on isolated infrastructure against real attack traffic: credential stuffing pools, deliberate malware injections, WAF bypass attempts. We report what happens, not what the marketing says.

03

Plain language

No hedging, no vendor-speak, no AI-generated filler. If we are not sure about something, we say so. If a product is bad, we say that too. Writing is audited against a specific anti-pattern list before publication.

04

Source trail

Every factual claim points back to where we verified it. News pieces explicitly list sources. Reviews document the test rig. If you want to second-guess a conclusion, we give you the material to do it.

05

Deliberate cadence

Some pieces take six weeks of testing. Some take an afternoon to report. We publish when the work is done, not when the editorial calendar calls for it. Quality over velocity.

06

Open correction

If we get something wrong, we correct it and say what changed. Revision trails matter more than pretending to be infallible. Send corrections to the tips address and we will act on them.

Affiliate policy, in plain terms.

The business model is transparent because obscuring it would undermine the editorial claim. Here is what you need to know.

01
Policy

Affiliate links are disclosed per article, not buried in a footer

Every review that contains affiliate links opens with a plain-language disclosure. Links marked with rel="sponsored" and visible call-outs in the piece. No dark patterns.

02
Policy

Rankings are not for sale

We have given mid-tier ratings to products whose affiliate programs we participate in, and high ratings to free tools with no affiliate revenue. The rating model is published. The evidence is cited. If the ranking changes we say why.

03
Policy

No sponsored content

No paid placements, no “partner spotlights”, no vendor-authored guest posts framed as editorial. Every piece published here is written by the WP Spear team on our own schedule, for our own editorial reasons.

04
Policy

No Google tracking on reader behaviour

We do not run Google Analytics. We do not run any third-party analytics. We look at server logs occasionally when something breaks. Reader privacy is the default, not a premium feature.

Who writes this.

WP Spear publishes under a single editorial byline. The team includes WordPress security researchers, incident responders, and site administrators with experience across enterprise and small-business WordPress environments. The byline is intentional, not evasive.

01
Why a single byline

The publication is the author, not the individual

Readers should trust the editorial standard, not the name of the person who happened to draft a particular piece. A single byline makes the publication accountable for its whole output rather than letting any one contributor accumulate outsized authority. It is also how most serious trade publications have worked since the 1890s.

02
When named bylines appear

Guest research and post-mortem contributors

If a guest researcher contributes to a technical post-mortem or a named expert consents to be quoted, they get a named byline on that specific piece. Otherwise every pillar, review, and news brief is published under the WP Spear team byline.

03
Editorial oversight

Published since Q3 2017

The publication has been operating under variations of this editorial standard since its founding. Some pieces in our archive have been revised to match current standards. The masthead, the voice, and the editorial position have stayed intentionally consistent across the years.

Get in touch.

We accept tips on active incidents, responsible-disclosure vulnerability reports, story pitches, and corrections. We do not accept sponsored placements or pay-to-review requests. Please read the category below before reaching out.

Incident tips

[email protected]

Active WordPress compromises, plugin-level disclosures, supply-chain anomalies, or anything on the security beat we should be reporting on. Include technical detail; we verify before we publish.

Vulnerability disclosure

[email protected]

Security issues in wpspear.com itself. PGP available on request. Coordinated disclosure preferred; we commit to acknowledging reports within 48 hours and patching verified issues before publication.

Editorial

[email protected]

Story pitches, corrections, product-review requests, press inquiries, permissions to quote. Replies typically within a business week. Pay-to-review requests are declined; please do not waste either party’s time.

Scroll to Top