
WordPress User Roles: Who Really Has The Keys
Every WordPress site has an account nobody remembers creating.
17 posts filed here.

Every WordPress site has an account nobody remembers creating.

The worst moment of a hacked site is not the discovery. It is the next ten minutes.

Your site can look perfectly fine to you and still be selling pills to Google.

A security grade is only useful if it tells you what it did not check.

A vulnerability feed can tell you what is vulnerable. It cannot tell you which of your WordPress sites…

Short answer: deploy the four low-risk directives today, run everything else in report-only mode for a week…

Short answer: WordPress sets HttpOnly on its authentication cookies and sets Secure conditionally when the…

Short answer: two wordpress security headers carry real benefit and cannot break anything, so set them now on…

Short answer: block wordpress xmlrpc on most agency sites, after checking that nothing on the site actually…

Short answer: a useful wordpress vulnerability scanner reads what is actually installed on a site and matches…

Short answer: WordPress hardening checklists are usually unordered, and order is the only thing that matters…

Short answer: a WordPress MCP connection does not give an agent “access to your site” as a single switch. It…

Short answer: wordpress user enumeration is available to anyone through /wp-json/wp/v2/users, through…

Short answer: as of 5 September 2026, at least 32.8% of WordPress installs ran a PHP branch that receives no…

Short answer: if WP_DEBUG_LOG is set to true, WordPress writes errors to wp-content/debug.log, which sits…

Short answer: a wp-config exposed to the internet is almost never wp-config.php itself. PHP executes that…

Short answer: when a wordpress plugin removed from repository is sitting on a site, nothing happens. It stays…