Topic
Authentication
Posts in this archive
3 insights
-
Passkeys for WordPress: when 2FA isn’t enough anymore.
The standard WordPress account security posture in 2024 looks roughly like: enforce strong passwords, require 2FA via TOTP, hope for the best. That’s been adequate...
Read the article
-
XML-RPC, REST, and the WordPress surfaces still leaking attack surface.
Every WordPress install ships with two API surfaces enabled by default. /xmlrpc.php has existed since the late 2000s, originally for desktop blogging clients that nobody...
Read the article
-
WordPress security isn’t a plugin problem.
Most WordPress sites have a security plugin. Most still get hacked. The disconnect is structural — the dangerous problems are architectural, and a hardening plugin won't fix them. What real WordPress security hardening looks like, layer by layer.
Read the article
No insights match the current filters. Clear filters to see everything.
Let's talk about what you're building
No proposals. No pitch decks. Just a conversation about your project and whether I'm the right fit to build it.
Start a Conversation