Here, we’ll explain the security risks posed by various files left sitting in your WordPress directory.
We will explain a type of backdoor—one that lacks a main malware component—which has been running rampant on WordPress recently (and for which we have confirmed a large number of infections).
If an unfamiliar administrator has been added to WordPress, we’ll explain how to determine whether that administrator is unauthorized and what steps to take.
Here, we’ll explain how to prepare for the era when AI starts attacking WordPress.
Here’s how to handle situations where your WordPress access logs contain a large number of “unfamiliar URLs” or “login page” entries.
We will explain the practical workflow—from the public disclosure of a WordPress plugin’s CVE to identifying the scope of impact within the company and implementing emergency measures.
Is Changing a Database Table Prefix Really Effective? Let’s Examine This Using Actual Attack Logs.
Here, we’ll explain how to monitor and respond to WordPress vulnerability information within your organization.
We’ll explain typical patterns of malicious code embedded in WordPress’s `wp_posts` and `wp_options` tables as a result of malware infection, as well as how to distinguish it from legitimate code. Malware Infection and Tampering of the WordPress Database In the event of a malware
Here’s how to prevent site-wide warning messages caused by failed automatic renewals of free SSL (Let’s Encrypt).
I’d like to discuss the issue that security measures for many WordPress sites tend to focus too much on protecting the login process.
Here’s a guide on how to regain administrator privileges after the person in charge of your WordPress site—which you had outsourced to a production company—has resigned or gone out of business.
The site looks normal, but search results are flooded with product pages or appear in Chinese—here’s an explanation of how to detect and completely remove SEO spam.
Here’s a guide on how to restrict access to your WordPress site to your own country.
In this article, I’ll explain the minimum code-level security measures that sole proprietors who use custom WordPress themes (or themes custom-built by a development company) should implement.
If you think your site is running slowly, it might actually be a brute-force attack—or a DDoS attack. Here’s how to identify these attacks and what measures even small-scale sites can take to defend against them.
If Google displays a “This site is dangerous” warning, we’ll explain the actual steps to have the Safe Browsing flag removed and the reality of the review process.
Slider Revolution (RevSlider) case study will explain the risks of “plug-ins that are out of license or have been moved to paid” and how to deal with vulnerabilities of such plug-ins.





















