September 2026 - Currency pass
- Protect The Shire cooldown corrected to six hours, and the automated release review that now blocks bad releases added to Chapters 8 and 12
- Patchstack's 2026 figures on vulnerability volume and time to exploitation added to Chapter 8
- Elementor Pro's exploited file-upload flaw added to Chapter 2 as the worked example for blocking PHP in uploads
- WordPress 7.1 and the September core security initiative noted in Chapter 2
- Apache examples moved to 2.4
Requiresyntax throughout; the 2.2Orderform fails silently on current servers wp-config.phppermissions made consistent at440across every chapter- The crisis runbook now matches Chapter 11 on stopping PHP rather than using maintenance mode
- PHP and Ubuntu support windows restated as fixed dates
August 2026 - WordPress 7.0 and the AI agent stack
- New Chapter 14 on AI agents and the MCP attack surface introduced in WordPress 7.0
- Updated the hosting chapter for current PHP support and the Imagick/Ghostscript RCE class
- Expanded the Application Passwords guidance now that agents authenticate with them
- Added coverage of the plugin update cooldown ("Protect The Shire") to the plugin and maintenance chapters
- Added a print-quality PDF edition, included with every purchase and downloadable from the reader. The web reader remains the canonical, continuously updated version; the PDF is a dated snapshot of it
May 2026 - Hardening additions
- Expanded coverage of file and information leaks at the server level
- Added a working example for restricting origin traffic to Cloudflare's IP ranges
- New guidance on auditing the must-use plugins folder for unauthorised files
April 2026 - Initial release
- All 13 chapters published
- Foreword, disclaimer, and outro added
- Covers WordPress 6.x, PHP 8.3 and 8.4, current plugin landscape as of April 2026