WP Secure Audit

The WP Secure Audit Blog

Notes from the field: real findings, breach post-mortems, and honest takes on WordPress security.

PENETRATION TESTING Aug 2026

The State of WordPress Security in 2026

A comprehensive look at recent vulnerabilities, shifting exploit vectors, and why manual penetration testing remains the ultimate defense line.

Read article arrow_forward
PENETRATION TESTING Jul 2026

What Automated Scanners Miss in WordPress Checkout Flows

A walkthrough of a business-logic flaw we found in a WooCommerce coupon system that no scanner would ever catch.

Read article arrow_forward
INCIDENT RESPONSE Jul 2026

Anatomy of a Backdoor: A Real Cleanup Case Study

How a single outdated contact-form plugin led to a persistent backdoor, and how we traced it back to patient zero.

Read article arrow_forward
HARDENING Jun 2026

Why 'Just Update WordPress' Isn't a Security Strategy

Updates matter, but they're one control among many. Here's what actually reduces breach risk long-term.

Read article arrow_forward
PLUGIN SECURITY Jun 2026

Reviewing 50 Popular Plugins for Insecure Direct Object References

Our research team's findings after manually reviewing the top 50 WordPress.org plugins by install count.

Read article arrow_forward
MONITORING May 2026

The 11-Minute Window: How Fast Attackers Move After a Plugin CVE Drops

Data from our monitoring clients on how quickly opportunistic scans begin after a public vulnerability disclosure.

Read article arrow_forward
COMPLIANCE May 2026

Mapping WordPress Controls to PCI-DSS for E-Commerce Sites

A practical breakdown of which WordPress-specific controls actually matter for PCI-DSS scope.

Read article arrow_forward
Chat on WhatsApp