Section
Security
Hardening, vulnerabilities and pragmatic compliance for small sites.
Read the guide: Self-hosting WordPress: the guide
7 articles
Chrome ships an emergency fix for an actively exploited V8 flaw (CVE-2026-85046)
Google shipped an emergency Chrome update on 4 September 2026 to patch CVE-2026-85046, a type-confusion bug in the V8 engine…
/ 4 min
Content-Security-Policy: building a policy that protects without breaking the site
A Content-Security-Policy is an HTTP header that limits the impact of script injection by filtering allowed sources. This guide walks…
/ 5 min
Next.js ships a critical patch: two remote code execution flaws fixed in 16.3.3 and 15.5.24
Next.js has shipped 16.3.3 and 15.5.24 on short notice, fixing two critical unauthenticated remote code execution flaws. One hits Windows-hosted…
/ 3 min
Cloudflare makes OAuth scopes optional for Wrangler and its MCP server
Cloudflare now lets you grant only part of the permissions Wrangler and its MCP server request. The change brings command-line…
/ 3 min
Next.js schedules a critical security release for 26 August
Vercel has announced a Next.js security release for 26 August 2026 that will fix one critical-severity flaw. Versions 16.3.3 and…
/ 3 min
Content Security Policy: building one that holds
A well-built Content Security Policy blocks injected scripts from running without breaking the site, provided it is rolled out in…
/ 6 min
WordPress hardening: the minimal security baseline
Wordfence, Fail2ban and application passwords: three components, half a day, and nearly all automated attacks stop having any effect.
/ 3 min