Press Esc to close

Articles

General updates and articles.

August 21, 2026

Hardening wp-config.php : 5 Essential Constants and Rules to Lock Down Your WordPress Configuration

Every WordPress site has a single point of failure that holds the keys to the entire infrastructure: wp-config.php. It stores your database credentials, system paths, cryptographic salts, and runtime configuration. If they gain write access, injecting persistent backdoors or hijacking the entire application takes just seconds. Directory traversal attacks – where automated bots servers attempting […]

Read Notes →
August 21, 2026

WordPress File Permissions Demystified: Why 777 is a Trap and How to Protect Your Uploads Directory

When troubleshooting a broken plugin, a failing media upload, or a caching error, you will inevitably encounter forum advice suggesting: “Just chmod 777 the folder to fix it.” Never do this. Setting permissions to 777 is the ultimate security surrender. A significant portion of WordPress compromises don’t come from zero-day exploits, but from basic misconfigurations […]

Read Notes →