Author: Austin Ginder
From a 7 KB file to a 13-year backdoor operation
Most plugin closures are uneventful. A developer stops responding, wp.org pulls the plugin, the listing goes dark, and that is the end of it.…
Gravity SMTP Exploit Campaign
The last few weeks have been whack-a-mole with my Mailgun account. My Mailgun account kept getting locked. I would clear a compliance issue, watch…
So you get hit with a credit card skimmer, what now?
An email landed in my inbox at 6:29 PM on a Tuesday. My customer had forwarded it from SecurityMetrics, whose Shopping Cart Monitor service…
Teaching AI To Do Your Work
I migrate WordPress sites every week. I have for years. I built tools to automate most of the migration. A bash utility called _do…
Lightweight Performance Monitor built in Bash.
A customer’s WooCommerce store was crashing every afternoon. Not a little slow. Completely unreachable. 503 errors for eight minutes at a time, then it…
WordPress.org Closed 83 WPFactory Plugins, Let’s Review
Last week WordPress.org closed 83 plugins from WPFactory. The closure caught their Algoritmika and WBW Plugins accounts too. Same parent company. There was a…
The Great Security Reset of 2026
February 2026 started like any other month. Then the security alerts started flooding in. Sites that had been clean for years were suddenly compromised.…
A Sold WordPress Plugin, a Hidden Update Channel, and 20,000 Backdoored Sites
I know you’ve heard this before however I’ve caught another plugin with a backdoor on wordpress.org. The plugin is Scroll To Top, slug scroll-top,…
WordPress Plugin Hijacked in 2020 Hid a Dormant Backdoor for Years
Twelve sites in our fleet were running a tampered version 5.2.3 of Quick Page/Post Redirect Plugin. The file hash did not match anything on…
GoDaddy Gave a Domain to a Stranger Without Any Documentation
What would you do if your organization had used a domain name for 27 years, and the registrar holding the domain seized it without…