Austin Ginder

  • SandyWP is awesome. And I exploited it.

    The owner of SandyWP asked me to look for bugs. I went in blind, drove the whole test with Claude Code, and found a single shared secret that unlocks every sandbox on the platform. Here is how, and why I still recommend it.

  • My AI Security Pipeline for WordPress Plugins

    One person with a Claude subscription and a local WordPress install can audit a large portion of the plugin repository. Here is the four-step pipeline, why every AI finding has to be proven before you trust it, and what the coverage actually looks like.

  • Anatomy of a WordPress.org supply-chain attack: the six ways in

    Six ways an attacker turns a trusted WordPress.org plugin into a foothold on your site, each drawn from a real campaign I have traced, with the code that made it work. Plus the one method you cannot scan for, and what actually catches all of them.

  • The hall of shame for WordPress admin notices

    I have wanted a public database of WordPress admin notices for years. Every WordPress professional knows the feeling. You log into /wp-admin/ to do one small thing, and the top…

  • From a 7 KB file to a 13-year backdoor operation

    Most plugin closures are uneventful. A developer stops responding, wp.org pulls the plugin, the listing goes dark, and that is the end of it. My WP Beacon scanner flags these…

  • Gravity SMTP Exploit Campaign

    The last few weeks have been whack-a-mole with my Mailgun account. My Mailgun account kept getting locked. I would clear a compliance issue, watch everything come back online, and a…

  • Hand-drawn illustration showing a credit card skimmer attack: checkout form being replaced, attacker receiving WebSocket payload, and the investigator analyzing _wfacp_global_settings

    So you get hit with a credit card skimmer, what now?

    An email landed in my inbox at 6:29 PM on a Tuesday. My customer had forwarded it from SecurityMetrics, whose Shopping Cart Monitor service had caught a script running on…

  • Teaching AI To Do Your Work

    I migrate WordPress sites every week. I have for years. I built tools to automate most of the migration. A bash utility called _do that handles backups and migrations over…

  • Lightweight Performance Monitor built in Bash.

    A customer’s WooCommerce store was crashing every afternoon. Not a little slow. Completely unreachable. 503 errors for eight minutes at a time, then it would come back, then crash again.…

  • WordPress.org Closed 83 WPFactory Plugins, Let’s Review

    Last week WordPress.org closed 83 plugins from WPFactory. The closure caught their Algoritmika and WBW Plugins accounts too. Same parent company. There was a report on wp-content.co about a suspected…