Technote

Security

Vulnerabilities, hardening, permissions, login protection and backups — closing the routes into a WordPress site one at a time.

13 articles· Security

Security Practical

The first hour after you discover a compromise

The most common mistake in this moment is deleting things in a hurry. Here is what to stop first, what to preserve, and in what order to recover…

Founders 8 min read

Security Practical

Making repeated login attempts pointless

Rate limiting and moving the login URL are recommended in the same breath, but they do different jobs. Here is an honest account of what each one does…

Founders 7 min read

Security Practical

SSL is on, so why is there no padlock?

The certificate is fine, yet the address bar shows a warning. The cause is usually one leftover http:// inside the page — and there is a set order…

Founders 7 min read

Security Practical

How far a nearly-free backup really reaches

The question is not whether you have a backup but how many hours it takes to be back. A free setup goes a long way — as long…

Founders 6 min read

Security Practical

What actually belongs in a privacy policy

Copy someone else's policy and you end up declaring data you never collect. There are really only five questions to answer.

Founders 9 min read

Security Practical

A backup you have never restored is not a backup

Sites are lost with backups in place. Usually not because the backup was missing but because nobody ever checked the conditions for restoring it — an hour's work.

Founders 6 min read

Security Intro

What happens while you put off updates

A vulnerability sits quietly and then, one day, becomes public. A clock starts at that moment — and it stops when you press update.

Founders 6 min read

Security Intro

What one properly made admin account prevents

The login screen is the most-knocked door on your site. Get the username, the password and the second factor right and most of that knocking becomes pointless.

Founders 7 min read

₩270,000 · Join the program