Tag

wp-cli

All posts in this stream, newest first.

User Roles and Least Privilege in WordPress

Most WordPress breaches spread further than they should because too many accounts have Administrator access. Here is how to map people to the right built-in roles and audit stale accounts before someone else finds them.

by Robbie·Jul 21, 2026·5 min read

XML-RPC: The Legacy Door Most Sites Should Close

xmlrpc.php was built for a web that no longer exists, and today it mostly serves attackers looking for brute-force amplification and DDoS leverage. Here is how to shut it down cleanly, or lock it down for the integrations that still need it.

by Robbie·Jul 18, 2026·5 min read