Section
Security
Hardening, vulnerabilities and pragmatic compliance for small sites.
Read the guide: Self-hosting WordPress: the guide
14 articles
npm Opens Dist-Tag Management to Trusted Publishing, No Token Needed
npm can now move dist-tags such as “latest” or “next” using the short-lived OIDC credentials from trusted publishing, with no…
/ 3 min
WordPress: A Critical Flaw Under Active Attack Five Days After Its Patch
Patched on September 22 in WordPress 7.1.2, CVE-2026-87902 is now under heavy scanning: more than 30,000 IP addresses probed sites…
/ 3 min
Two Critical Flaws Hit Widely Used WordPress Plugins
Two vulnerabilities rated 9.8 out of 10 affect Visual Composer Website Builder and the WAWP plugin for WooCommerce, letting unauthenticated…
/ 3 min
Drupal patches a critical remote code execution flaw in Webform
The Webform module ships around twenty security advisories in a single window, including a critical remote code execution flaw. Version…
/ 3 min
WordPress 7.1.1 ships an urgent fix for eleven security flaws
WordPress 7.1.1 closes eleven security flaws in core and the block editor, including an authenticated path traversal in REST templates.…
/ 3 min
Next.js ships a critical patch: two remote code execution flaws fixed in 16.3.3 and 15.5.24
Next.js has shipped 16.3.3 and 15.5.24 on short notice, fixing two critical unauthenticated remote code execution flaws. One hits Windows-hosted…
/ 3 min
Cloudflare makes OAuth scopes optional for Wrangler and its MCP server
Cloudflare now lets you grant only part of the permissions Wrangler and its MCP server request. The change brings command-line…
/ 3 min
Next.js schedules a critical security release for 26 August
Vercel has announced a Next.js security release for 26 August 2026 that will fix one critical-severity flaw. Versions 16.3.3 and…
/ 3 min
WordPress hardening: the minimal security baseline
Wordfence, Fail2ban and application passwords: three components, half a day, and nearly all automated attacks stop having any effect.
/ 3 min
WordPress 7.1.2 patches a critical file-inclusion flaw
WordPress 7.1.2 fixes a critical vulnerability that let an unauthenticated attacker force page-template resolution to include an arbitrary PHP file.…
/ 4 min