Elizabeth Sramek
18 published guides
InspectWP vs. WPDeeply: Which WordPress Security Analysis Tool Wins in 2026?
InspectWP is useful for seeing surface-level technology signals. WPDeeply is built for the next question: are the exact plugins and themes on your site tied to known CVEs,…
ForgetWP.com is Now a Part of WPdeeply.com WordPress Family
We don’t usually do “big announcement” posts. Most of what we publish here is tutorials, teardowns, and the occasional rant about a plugin that broke your site at…
WP Activity Log before 4.1.5 unauthenticated SQLi
Status: patched. This is a fix-verified writeup of an unauthenticated SQL injection we originally disclosed in WP Activity Log (then WP Security Audit Log, now sold by Melapress)…
WordPress Security Testing (2026 Update)
Short answer: you can’t verify a WordPress security vendor’s claims by reading their marketing page — you verify them by checking what’s actually testable: their CVE disclosure history,…
Plausible.io: Why You’re Going to Love It
Are you looking for a Google Analytics alternative — one that doesn’t collect personal data and skips cookies entirely? Then Plausible.io might be exactly what you’re after. We’ve…
WordPress Vulnerabilities — July 2026
What mattered in WordPress plugin security last month, and what to do about it.
How to Select the Best Business to Work With (as a Solo WordPress Entrepreneur)
There’s a specific kind of dread that comes from a plugin update breaking a client site at 11pm on a Sunday, and you’re the only person who’s going…
WordPress Security Plugins Compared: What Each Type Actually Does
Firewalls, scanners, backup tools and vulnerability monitors solve different problems. Mixing them up leaves gaps.
WordPress Vulnerabilities — June 2026
June’s WordPress plugin security disclosures, and the recurring themes behind them.
Remote Code Execution in WordPress, Explained
The worst class, how plugins get there, and why cleanup is not the same as patching.