Security & Malware Defense
Hardening WordPress core, malware incident remediation, and vulnerability prevention.
Implementing Two-Factor Authentication (2FA) in WP
Step-by-step guide to implementing two-factor authentication (2FA) in WordPress using RFC 6238 TOTP and the authenticate filter.
Preventing SQL Injections and XSS in WordPress Plugins
Learn best practices for preventing SQL injections and XSS in WordPress plugins with $wpdb->prepare() and output escaping functions.
Authenticating Headless WordPress Requests with Passwords
Learn best practices for authenticating headless WordPress requests using native Application Passwords, Bearer tokens, and JWT.
WordPress Hardening Checklist: wp-config & Directives
Complete WordPress hardening checklist: lock down wp-config.php, block upload directory execution, and prevent brute-force attacks.
Detecting and Cleaning WordPress Malware & Backdoors
Incident response guide for detecting and cleaning WordPress malware: remove obfuscated PHP webshells and verify file checksums.
One letter,
once a Month.
Build logs, a worked example, and one tool we're using. Free, 3 minutes to read.