Section
Security
Hardening, vulnerabilities and pragmatic compliance for small sites.
Read the guide: Self-hosting WordPress: the guide
14 articles
npm Opens Dist-Tag Management to Trusted Publishing, No Token Needed
npm can now move dist-tags such as “latest” or “next” using the short-lived OIDC credentials from trusted publishing, with no…
/ 3 min
WordPress: A Critical Flaw Under Active Attack Five Days After Its Patch
Patched on September 22 in WordPress 7.1.2, CVE-2026-87902 is now under heavy scanning: more than 30,000 IP addresses probed sites…
/ 3 min
Two Critical Flaws Hit Widely Used WordPress Plugins
Two vulnerabilities rated 9.8 out of 10 affect Visual Composer Website Builder and the WAWP plugin for WooCommerce, letting unauthenticated…
/ 3 min
Drupal patches a critical remote code execution flaw in Webform
The Webform module ships around twenty security advisories in a single window, including a critical remote code execution flaw. Version…
/ 3 min
WordPress 7.1.2 patches a critical file-inclusion flaw
WordPress 7.1.2 fixes a critical vulnerability that let an unauthenticated attacker force page-template resolution to include an arbitrary PHP file.…
/ 4 min
OpenAI Breached Through an ImageMagick Flaw Exploited With Claude Opus 5
Researchers chained a flaw in the libheif library used by ImageMagick with a single sign-on weakness to reach OpenAI employee…
/ 4 min
WordPress 7.1.1 ships an urgent fix for eleven security flaws
WordPress 7.1.1 closes eleven security flaws in core and the block editor, including an authenticated path traversal in REST templates.…
/ 3 min
Chrome ships an emergency fix for an actively exploited V8 flaw (CVE-2026-85046)
Google shipped an emergency Chrome update on 4 September 2026 to patch CVE-2026-85046, a type-confusion bug in the V8 engine…
/ 4 min
Content-Security-Policy: building a policy that protects without breaking the site
A Content-Security-Policy is an HTTP header that limits the impact of script injection by filtering allowed sources. This guide walks…
/ 5 min
Next.js ships a critical patch: two remote code execution flaws fixed in 16.3.3 and 15.5.24
Next.js has shipped 16.3.3 and 15.5.24 on short notice, fixing two critical unauthenticated remote code execution flaws. One hits Windows-hosted…
/ 3 min