WPDeeply Research
15 published guides
How to Prevent Reinfection
Why cleaned sites get hit again within weeks, and the five things that stop it.
Should You Delete Inactive WordPress Plugins?
Deactivated is not the same as gone. What an inactive plugin can and cannot do.
Cross-Site Scripting (XSS) in WordPress, Explained
Stored, reflected and why “it only affects admins” is the wrong conclusion.
Securing wp-config.php
The one file that holds your database credentials — permissions, constants and salts.
SQL Injection in WordPress, Explained
What SQL injection is, why WordPress plugins keep producing it, and what it means when your site has one.
Signs Your WordPress Site Has Been Hacked
The symptoms owners actually notice first, and what each one usually means.
How to Check If a WordPress Plugin Is Safe
Five checks, in order of usefulness, before you install a WordPress plugin.
How to Detect WordPress Malware
What to look at, in what order, when you suspect a WordPress site is infected.
A Plugin Was Removed From WordPress.org. What Does That Mean?
Closed, removed, or just gone — how to read a missing plugin listing, and what to do.
The WordPress Security Checklist
Fourteen items, ordered by how much risk each one removes per minute spent.