Security Headers for WordPress: HSTS, CSP and Friends
A practical, non-breaking rollout order for HSTS, CSP, and the other browser-enforced security headers, plus how to verify each one actually took effect.
All posts in this stream, newest first.
A practical, non-breaking rollout order for HSTS, CSP, and the other browser-enforced security headers, plus how to verify each one actually took effect.
A web application firewall filters out a lot of junk before it ever reaches PHP, but it is not a substitute for patching, strong credentials, or a real backup plan. Here is what it actually buys you.
WPBeginner's latest tutorial breaks down free, built-in WordPress settings and layered techniques site owners can use to stop comment, form, and registration spam without expensive tools.
wp-config.php is the quiet file that controls half your site's security posture. Here is how to rotate its secrets, lock down its constants, and keep it out of anywhere a backup or backup archive might leak.
WordPress 7.0.2 is a forced security release fixing one critical and one high severity vulnerability, including a REST API bug that could lead to remote code execution. Backports are available for 6.8 and 6.9.
xmlrpc.php was built for a web that no longer exists, and today it mostly serves attackers looking for brute-force amplification and DDoS leverage. Here is how to shut it down cleanly, or lock it down for the integrations that still need it.
Cloudflare deployed new firewall rules protecting all customers, including free plans, from an unauthenticated remote code execution flaw and a related SQL injection bug in WordPress. Site owners should still patch immediately.
wp-login.php is the single most attacked URL on the open web. Here is the layered defense, strong authentication, lockouts, bot challenges, and a plan for what to do when credential stuffing shows up in your logs.
A clear-headed walkthrough of LCP, INP, and CLS on WordPress, plus the order of fixes that actually moves the needle instead of chasing every red number in the report.
About 40 students from three universities earned the first AI Leaders Micro-Credential, a workforce-focused program that pairs generative AI skills with real contributions to WordPress's open source codebase.