Why Your Site Gets Attacked Even Though “Nobody Needs It”

6 days ago

GPT-6 Astra beat all 48 levels of “I’m Not a Robot”

Neal Agarwal’s I’m Not a Robot is 48 CAPTCHAs in a row, with a certificate at the end declaring you a human being. GPT-6 Astra played it start to finish and got the certificate. Every level is a new interface with rules nobody explains, and the model figured out what each one wanted and clicked. CAPTCHAs only ever worked because machines couldn’t do that.

We’ve kept them around out of habit for a while now. If a checkbox is the only thing between your signup form and a thousand fake accounts, you should probably assume it’s decorative.

The First 24 Hours: What a Hacked WordPress Site Looks Like From the Owner’s Chair

1 week ago

MCP in WordPress: Why Your Site Is Learning to Talk to AI Agents

WordPress now has official MCP support. MCP, the Model Context Protocol, is the interface that assistants like Claude, ChatGPT and Cursor use to call external tools.

It works through two pieces. Plugins and themes register individual actions through the Abilities API, and the MCP Adapter, which lives in the official WordPress GitHub organization, exposes those actions as tools an agent can call. WordPress 6.9 or newer is required.

If you try it, do it on staging first, and authenticate the connection as a limited user with an application password you can revoke. The agent gets exactly the permissions that account has, and nothing about MCP changes that.

Vibe Coding Came to WordPress — and Brought Its Holes With It

Backups That Won’t Save You: The Classic Mistakes of WordPress Backup Strategy

2 weeks ago

Claude Cowork now ships with its own built-in browser

Claude Cowork now has its own browser. When a task involves a website, a panel opens next to the chat and Claude clicks, reads and fills forms in there while you carry on with whatever you were doing. That browser has nothing to do with yours. Your tabs and passwords stay invisible to it, which honestly removes our biggest reservation about letting agents loose on the web.

The Claude in Chrome extension survives and still makes sense for the page you’re already sitting on. The new browser is for work you want to hand off completely and forget about for twenty minutes. Rolling out on Pro, Max and Team plans.

The EU Cyber Resilience Act: What It Actually Means for Your WordPress Project

2 weeks ago

Five Hours to Mass Exploitation: How AI Changed the Speed of WordPress Attacks

WordPress security used to run on a comfortable cycle: a flaw is disclosed, a patch appears, owners update eventually.

Patchstack’s State of WordPress Security in 2026 puts the median gap between disclosure of a critical flaw and mass exploitation at five hours. Eleven thousand vulnerabilities were logged in 2025, nine in ten in plugins, and nearly half had no fix on the day they went public.

The driver is automation: a patch goes into AI tooling and scanners sweep the internet hours later.

Two things still work. Auto-updates, with staging behind them. And a firewall — when a flaw ships without a patch, a WAF rule is often the only protection there is.

Why Half of WordPress Plugin Developers Ignore Vulnerabilities

Book a call
Contacts

    Tell us about your project — we'll get back to you within 24 hours.

    replies within 24h

    Thank you!
    Thanks for your email — we will get back to you shortly.