Everything filed.
The full catalogue. Pieces organized by desk, cross-referenced by what the work is actually about. Updated as new work lands and as old work gets revisited. If you are looking for a specific thing and not finding it here, we probably have not filed it yet.
Hardening.
Closing the attack surface before the attack arrives. Configuration-layer work, update policy, access control, and the defensive model under all of it.
How to secure a WordPress site: the complete hardening model
Strategic guide to WordPress security. Threat model, eight defensive layers, automation vs. manual operation, and the priority order when starting from scratch.
The fifteen-minute WordPress security checklist we follow
Eight steps in a specific order. The ones that close the attack surface real scanners actually touch. Commands and config, not feature talk.
WordPress malware protection: the four layers that actually work
Malware protection on WordPress is not one product. Four layers, the tradeoffs at each, and plugin recommendations by site profile.
WordPress DDoS protection: target, weapon, and what stops both
The WordPress-specific story: your site is both a DDoS target and a DDoS weapon. XMLRPC + pingback surfaces to close, origin-IP hiding, rate-limiting, and the host tier you need.
News.
Disclosures, campaigns, plugin lifecycle events, and the occasional post-mortem. What the WordPress security beat looks like when nobody is selling you anything.
The Essential Plugin backdoor: how 31 WordPress plugins went malicious in eight hours
Sold on Flippa for six figures. Dormant for eight months. Activated April 6. The deserialization gadget, the Ethereum C2, and what to do if you were running any of the 31 affected plugins.
The Plausible Analytics speed module: how a performance shortcut could switch off your firewall
An unanchored substring match let anyone unload every plugin but Plausible on a request of their choosing, firewall included. Reported, patched in 2.5.8, written up here.
Protect the Shire and the two threats one update button cannot both solve
WordPress.org’s plugin-update delay is a real defense against poisoned releases and a real tax on security fixes. The tradeoff, and what to do about it.
Incident.
Your site is hacked. What happens next. Incident timelines, cleanup procedures, post-mortems on client work, and the end-to-end methodology we run when a compromise lands on a site we manage.
WordPress malware removal: the procedure we run on client sites
Identify, clean, close the door, verify. The recently-modified-file diff, the IOCs we actually look for, and why the reinfection arrives forty-eight hours later.
How to fix a hacked WordPress site: the first-hour playbook
Before the cleanup, the decisions. Preserve evidence, contain access, pick one of three realistic routes out, and tell the right stakeholders in the right order.
The WordPress pharma hack: cleanup, then the real work
SEO-spam incident response. The cloaking mechanism, the cleanup procedure, and the four-to-eight-week arc of reclaiming your search presence after Google indexes spam under your domain.
Reviews.
The security plugins we install, evaluated on technical merit rather than commission rate. Six weeks of testing per plugin, measured against live attack traffic on isolated infrastructure.
Best WordPress security plugins, adjusted for reality
Five plugins tested on live installs against real attack traffic. Where each one wins and where it does not.
Wordfence Review: the plugin we install by default
Firewall-plus-scanner suite handling most of the defensive stack in one plugin. When Premium is worth $149 and when Free is enough.
Patchstack Review: virtual patching, measured
CVE-intelligence firewall that ships virtual patches before you update. What it catches Wordfence does not, and what it does not try to do.
MalCare Review: the cleanup plugin we install when prevention fails
Tested against three deliberate malware injections. First-try cleanup timing, pricing tiers, and when unlimited cleanups pay off.
Sucuri Review: cloud WAF, cleanup service, and who it is actually for
The agency-tier security bundle from GoDaddy. Why most WordPress sites should use Cloudflare instead, and the operators for whom Sucuri is the right call.
Solid Security Review: the hardening plugin, honestly assessed
Formerly iThemes Security. Best free-tier value for hardening and 2FA, with one major blind spot (no malware scanner).