Author: Austin Ginder
No web host tested the next WordPress core.
WordPress 7.1 plus WP Rocket plus Elementor Pro took 37% of our WP Rocket sites down. Core was fine. The combination was not. Hosts…
How I uncovered an unauthenticated Elementor Pro RCE for a record Wordfence bounty
How directing AI (not being a career bounty hunter) produced an unauthenticated Elementor Pro RCE, a $15,600 Wordfence bounty, and a new chain-hunting skill…
What visibility do you have when releasing a plugin directly on GitHub?
I ship side projects on GitHub instead of WordPress.org. Here is what stars, release asset downloads, and a tiny local dashboard can tell you…
Gutenberg is huge for a reason. That does not mean every editor has to be.
Classic Editor still holds millions of installs. The block editor is a multi-megabyte platform. Minn Admin stores the same Gutenberg markup from a single…
3 Failed WP-Admin Projects, Let’s go for the 4th!
Two weeks ago I replaced /wp-admin/ on my own WordPress sites with /minn-admin/. This is my fourth attempt at building a WordPress backend replacement.…
Grok Build finally made my AI email triage a real workflow
process-emails drains noise. draft-email writes replies. /email-worker plus Grok Build todos is the first time hammering the customer queue felt as fast as the…
SandyWP is awesome. And I exploited it.
The owner of SandyWP asked me to look for bugs. I went in blind, drove the whole test with Claude Code, and found a…
My AI Security Pipeline for WordPress Plugins
One person with a Claude subscription and a local WordPress install can audit a large portion of the plugin repository. Here is the four-step…
Anatomy of a WordPress.org supply-chain attack: the six ways in
Six ways an attacker turns a trusted WordPress.org plugin into a foothold on your site, each drawn from a real campaign I have traced,…
The hall of shame for WordPress admin notices
I have wanted a public database of WordPress admin notices for years. Every WordPress professional knows the feeling. You log into /wp-admin/ to do…