-
Why "Self-Healing" WordPress Malware Keeps Coming Back
8 min read
You deleted the files and they reappeared in under a second. That is not the malware repairing itself. It is code running before WordPress does, and until you find it you are cleaning symptoms. Here is where it hides.
Read the post → -
WordPress 7.0 Put an AI Agent Behind Your Login. Here Is What That Means.
5 min read
WordPress 7.0 shipped an AI and agent stack into core, including an MCP adapter that lets external agents drive your site over Application Passwords. It is useful and it is a real new attack surface. Here is what changed and how to keep it from being the thing that gets you compromised.
Read the post → -
How to Remove Malware From a WordPress Site
6 min read
A calm, ordered process for cleaning malware out of a hacked WordPress site, why a plugin scan alone rarely finishes the job, and how to make sure it does not come straight back.
Read the post → -
Setting Up Two-Factor Authentication on WordPress, Properly
6 min read
Two-factor authentication does more for a WordPress admin login than almost any other single change. Here is which plugin to use, how to enforce it by role, why SMS is the wrong choice, and how to set it up without locking yourself out.
Read the post → -
A WordPress Backup Strategy That Actually Works When You Need It
7 min read
Most WordPress backups fail at the only moment they matter, the restore. Here is the backup strategy I run for client sites, why a backup on the same server is not a backup, and how to know yours will actually work before you need it.
Read the post → -
WordPress Just Released Official AI Agent Skills. Here's What It Means for Security.
8 min read
The WordPress project shipped an official repo of AI coding-assistant skills in July 2026. Here's what it actually is, what it fixes, and why security-conscious developers should care without treating it as a substitute for review.
Read the post → -
Passkeys for WordPress Admins: The Actual Setup
7 min read
Passkeys have crossed the threshold from cool option to recommended default for WordPress admin logins in 2026. Core does not yet ship them. Here is the plugin, the configuration, and the specific things that will lock you out if you get them wrong.
Read the post → -
WordPress Auto Updates Are Not a Security Strategy
7 min read
Auto updates catch most of the routine plugin patching that would otherwise slip. They also happily push a compromised release to your site the moment one exists. Here is the workflow the ecosystem is moving to in 2026.
Read the post → -
WordPress vs Squarespace: Security Compared
12 min read
Squarespace has excellent platform security and one documented weak spot, which cost a dozen companies their domains in 2024. An honest 2026 comparison with WordPress, organised around where each one actually fails.
Read the post → -
The WordPress Plugin You Trusted Just Got Sold
8 min read
In April 2026 an attacker bought a portfolio of thirty WordPress plugins on Flippa, waited eight months, and pushed a backdoor into all of them at once. Here is what happened, why the emergency update didn't clean up the mess, and what it means for how you pick plugins now.
Read the post → -
WordPress vs Wix: Security Compared
9 min read
An honest, up-to-date comparison of what WordPress and Wix actually do for security in 2026, where each one is stronger, and how to choose without the marketing spin.
Read the post → -
Is WordPress Secure?
8 min read
A straight answer to the question people actually mean when they ask whether WordPress is secure, and the handful of things that decide whether any given site is safe or not.
Read the post → -
WordPress File Permissions and Database Security
9 min read
The two layers under the WordPress dashboard that decide how bad a compromise gets. What the correct file permissions actually are, and how to lock down your database properly.
Read the post → -
Lock Down wp-login.php, xmlrpc.php and wp-admin
7 min read
The three URLs that take the most attack traffic on any WordPress site, and the specific configuration that locks each one down without breaking anything.
Read the post → -
WordPress Security Headers, Explained Properly
8 min read
A practical guide to the HTTP security headers worth setting on a WordPress site, what each one actually does, and the configuration that works.
Read the post → -
Common WordPress Security Issues
8 min read
The WordPress security issues that actually get sites compromised, in order of how often they show up. What each one is, why it happens, and what fixes it.
Read the post → -
Should You Move wp-config.php Above the Webroot?
6 min read
Moving wp-config.php one folder up is standard WordPress advice. Here's what it actually protects against, what it doesn't, and when it's worth doing.
Read the post → -
The WordPress Security Checklist
5 min read
A practical, ordered WordPress security checklist covering hosting, core, logins, files, backups and monitoring, with the reasoning behind each step.
Read the post → -
What Your WordPress Host Won't Do For You
6 min read
Managed hosting protects the server, not your WordPress site. Here's the gap between what your host covers and what's actually left to you.
Read the post → -
Is My WordPress Site Hacked? Twelve Signs to Check
8 min read
A practical checklist for working out whether your WordPress site has been compromised, what to look at first, and what each sign actually means.
Read the post → -
The Best WordPress Security Plugins in 2026
6 min read
The WordPress security plugins I actually install in 2026, the ones I skip, and how they fit together as a stack.
Read the post → -
How to Harden WordPress
7 min read
What to actually change to harden a WordPress site, starting with wp-config and working outwards.
Read the post → -
How to Recover a Hacked WordPress Site Step by Step
7 min read
A calm, ordered run through of what to do when your WordPress site has been compromised, from taking it offline to closing the gap the attacker came in through.
Read the post →
Get the free WordPress Security Checklist
The security checks I'd run through on any WordPress site, delivered straight to your inbox.