Hardening
Configuration and access changes that reduce WordPress attack surface.
6
Guides
Security Hardener <= 2.4.4 - Subscriber+ Privilege Escalation via REST Users Permission Callback
CVE-2026-16149 is a high-severity Security Hardener flaw where user-enumeration protection can overwrite WordPress REST user endpoint capability checks, allowing Subscriber-level users to perform privileged user actions. Update to…
Security Headers Worth Setting
The four headers that earn their place on a WordPress site, and the one that needs care.
Protecting wp-admin and wp-login
What actually reduces risk on the two most attacked URLs in WordPress.
WordPress File Permissions, Correctly
The numbers that work, why 777 is never one of them, and what to check after an incident.
Securing wp-config.php
The one file that holds your database credentials — permissions, constants and salts.
The WordPress Security Checklist
Fourteen items, ordered by how much risk each one removes per minute spent.