Choosing and Updating Plugins Without Getting Owned
Most WordPress compromises start with a plugin, not core. Here is how to vet what you install, update on a schedule that catches problems early, and avoid the shortcut that causes the most damage.
All posts in this stream, newest first.
Most WordPress compromises start with a plugin, not core. Here is how to vet what you install, update on a schedule that catches problems early, and avoid the shortcut that causes the most damage.
A systematic way to find which plugin is eating your response time, using wp-cli, Query Monitor, and a disable-and-test method, then decide whether to configure, replace, or delete it.
WordPress isn't run by a company, it's built by a loose federation of volunteers, sponsored contributors, and review teams. Here's how that system actually works.
A plain-language look at how SQL injection actually works, why WordPress core rarely causes it, and the layered defenses that keep a real attack from becoming a real breach.
Every WordPress plugin runs on a business model, and that model predicts whether it will still be updated, secure, and compatible in two years. Here is how to read the signals before you build a site on top of one.