security

  • Fixing Jetpack Contact Form SPAM

    We have so many contact form plugins within the WordPress community. We also have several CAPTCHA systems available for these plugins, usually via Google reCaptcha or Cloudflare Turnstile. It’s all a lot to take in, and these plugins and services can add a lot of weight to a small site. Sometimes I prefer to use…

  • PHP 8.2 is rolling out now

    All sites should be running PHP 8.0+ by now given PHP 7.4 lifecycle ended late last year. PHP 8.0 will hit EOL later this year and sites should be upgrading at this time. PHP 8.1 was released in December 2021 and was succeeded by PHP 8.2 in December 2022. PHP 8.1 speeds-up WordPress 3.5% according…

  • Emailing secure messages

    How many times have you received a text with a password, an encrypted spreadsheet file and a separate email containing the password (sitting in the same mailbox!), or an unprotected Google Sheet? There’s better solutions! Here’s some worth taking a look at: For heavier security have a look at asymmetric cryptography (like PGP) Apps or…

  • You’re running PHP 8 by now, right?

    WooCommerce had a little blip in this week’s release of version 7.1.0 where the PHP requirement was bumped to PHP 7.4 prematurely. They’ve fixed it, supporting PHP 7.2+ at the moment, but took the opportunity to issue a warning that PHP 7.4 is losing security support in just two weeks time. See PHP supported versions.…

  • Who should have Administrator access?

    I often come across sites that have questionable WordPress administrator accounts. I work with clients to reduce this exposure. It’s dangerous offering full privilege accounts to anybody besides fully trusted and technically capable vendors and staff. Regular review is recommended since there tends to be shifts in staff and roles over time. Here’s why admin…

  • Giving out Administrator access

    Let’s say you’ve reported a bug that you’ve observed in a theme or plugin. Good job by the way! Should you provide the developer admin access to your production site so they can diagnose or repair the issue? ABSOLUTELY NOT!

Share this:

Blog categories

Note: I may receive compensation for referrals.

WP Engine - A smarter way to WordPress
The best email marketing tool, responsive templates, automations, Worldwide support, tracking and reports, Benchmark Email, free plan available
Sell everywhere. Use Shopify to sell in-store and online.
Klaviyo partner badge
Okendo Partner, certified
WooCommerce, the most customizable eCommerce platform for building your online business. Click to get started.
Jetpack, a stronger, customizable site without sacrificing safety. Click to get started.