Press Esc to close

Articles

General updates and articles.

August 21, 2026

The Silent Door Left Ajar: Why You Must Disable XML-RPC in WordPress Today

Most WordPress site owners obsess over strong passwords, two-factor authentication, and login page lockouts. Yet, on millions of servers, an old legacy protocol sits quietly in the background, listening for requests and letting automated bots hammer away at credentials without triggering standard security alerts: xmlrpc.php. Password attacks hitting XML-RPC occur at nearly the same rate […]

Read Notes →
August 21, 2026

Hardening wp-config.php : 5 Essential Constants and Rules to Lock Down Your WordPress Configuration

Every WordPress site has a single point of failure that holds the keys to the entire infrastructure: wp-config.php. It stores your database credentials, system paths, cryptographic salts, and runtime configuration. If they gain write access, injecting persistent backdoors or hijacking the entire application takes just seconds. Directory traversal attacks – where automated bots servers attempting […]

Read Notes →