Threat research, walkthroughs of real-world WordPress compromises (anonymised), plain-English explainers for site owners, and field notes from the RedSecLabs team. New posts roughly fortnightly.
Most WordPress sites don’t get hacked because someone targeted them personally. They get compromised because security was ignored until it was too…
WordPress security often gets framed as an all-or-nothing choice. Either you lock everything down with complex tools, or you do…
One email per post. Threat walkthroughs, agency playbooks, and product updates. Unsubscribe anytime.