Vibe Coding Came to WordPress — and Brought Its Holes With It

2 hours ago

GPT-6 Astra beat all 48 levels of “I’m Not a Robot”

Neal Agarwal’s I’m Not a Robot is 48 CAPTCHAs in a row, with a certificate at the end declaring you a human being. GPT-6 Astra played it start to finish and got the certificate. Every level is a new interface with rules nobody explains, and the model figured out what each one wanted and clicked. CAPTCHAs only ever worked because machines couldn’t do that.

We’ve kept them around out of habit for a while now. If a checkbox is the only thing between your signup form and a thousand fake accounts, you should probably assume it’s decorative.

Backups That Won’t Save You: The Classic Mistakes of WordPress Backup Strategy

1 week ago

Claude Cowork now ships with its own built-in browser

Claude Cowork now has its own browser. When a task involves a website, a panel opens next to the chat and Claude clicks, reads and fills forms in there while you carry on with whatever you were doing. That browser has nothing to do with yours. Your tabs and passwords stay invisible to it, which honestly removes our biggest reservation about letting agents loose on the web.

The Claude in Chrome extension survives and still makes sense for the page you’re already sitting on. The new browser is for work you want to hand off completely and forget about for twenty minutes. Rolling out on Pro, Max and Team plans.

The EU Cyber Resilience Act: What It Actually Means for Your WordPress Project

2 weeks ago

Five Hours to Mass Exploitation: How AI Changed the Speed of WordPress Attacks

WordPress security used to run on a comfortable cycle: a flaw is disclosed, a patch appears, owners update eventually.

Patchstack’s State of WordPress Security in 2026 puts the median gap between disclosure of a critical flaw and mass exploitation at five hours. Eleven thousand vulnerabilities were logged in 2025, nine in ten in plugins, and nearly half had no fix on the day they went public.

The driver is automation: a patch goes into AI tooling and scanners sweep the internet hours later.

Two things still work. Auto-updates, with staging behind them. And a firewall — when a flaw ships without a patch, a WAF rule is often the only protection there is.

Why Half of WordPress Plugin Developers Ignore Vulnerabilities

4 months ago

CodeGraph Cuts Claude Code Costs by 35% With Pre-Indexed Knowledge Graphs

CodeGraph is an open-source tool that builds a pre-indexed knowledge graph of your codebase, letting AI coding agents like Claude Code, Cursor, Codex CLI, and Hermes Agent query symbol relationships and call graphs instantly — instead of scanning files with grep and glob on every request.

Benchmarks across 7 real-world codebases in 7 languages show average savings of 35% on cost, 59% fewer tokens, 70% fewer tool calls, and 49% faster responses. The tool runs 100% locally via an MCP server, requires no Node.js to install, and auto-configures supported agents with a single interactive command.

We’re always testing new tools that push the limits of AI-assisted development — and a project sitting at nearly 15K GitHub stars isn’t something you walk past. CodeGraph can index routes, map call graphs, trace callers and callees, and assess edit impact before a single file is touched.

Google’s new tracking system bypasses VPN and Tor

Google allowed itself a rather controversial technology that it called unsuitable 6 years ago. What has changed and why was this decision made?

2 years ago

Have you heard anything about WebAssembly (Wasm)?

WebAssembly (Wasm) allows running code written in various programming languages (C, C++, Rust, and others) in the browser with near-native performance. In 2025, we expect Wasm to become even more widespread across several areas. For example, for developing high-performance web applications: Especially in areas such as online games, graphic editors, and scientific computing. The technology can also be used to port existing applications to a web foundation: without the need to rewrite them from scratch in JavaScript. Additionally, web application security will improve: thanks to strict isolation of Wasm code from the rest of the browser. Conclusion: Wasm is definitely a trend for 2025 that you should pay attention to!

Book a call
Contacts

    Tell us about your project — we'll get back to you within 24 hours.

    replies within 24h

    Thank you!
    Thanks for your email — we will get back to you shortly.