Topic

Authentication

Posts in this archive

3 insights

  1. Security Hardening 6 min read

    Passkeys for WordPress: when 2FA isn’t enough anymore.

    The standard WordPress account security posture in 2024 looks roughly like: enforce strong passwords, require 2FA via TOTP, hope for the best. That’s been adequate...

    Read the article

  2. Security Hardening 6 min read

    XML-RPC, REST, and the WordPress surfaces still leaking attack surface.

    Every WordPress install ships with two API surfaces enabled by default. /xmlrpc.php has existed since the late 2000s, originally for desktop blogging clients that nobody...

    Read the article

  3. Security Hardening 15 min read

    WordPress security isn’t a plugin problem.

    Most WordPress sites have a security plugin. Most still get hacked. The disconnect is structural — the dangerous problems are architectural, and a hardening plugin won't fix them. What real WordPress security hardening looks like, layer by layer.

    Read the article

Let's talk about what you're building

No proposals. No pitch decks. Just a conversation about your project and whether I'm the right fit to build it.

Start a Conversation