On the podcast today we have Oliver Sild.

Oliver has been working in the WordPress space for many years, and specifically with WordPress security, as one of the founders of Patchstack, formerly called WebARX.

Patchstack is a product which is designed to help you identify plugin vulnerabilities in your WordPress sites.

Over the past couple of years Patchstack has released an annual report about the state of WordPress security. The report for 2021 has just been released, and the podcast today is concerned with what they found out.

We talk about why they produce this report, and who the intended audience is. What are the main takeaways in terms of the overall security of WordPress Core, plugins and themes.

We then get into more specific details of what types of vulnerabilities and attacks seem to be prevalent in the WordPress space. Are there any trends which are useful to think about, and how WordPress security is managed by the community as a whole; are budgets and time typically allocated for prevention and restoration of websites?

Towards the end we talk about how some people have pushed back on the usefulness of the report. They’ve questioned the motivations of security companies to write such reports and the use of the language which they contain. Do they paint more of a negative picture in order to drive sales of their commercial solutions?

Useful links.

State of WordPress Security in 2021 Report

Patchstack website

Is WordPress security getting better or worse?

Rebuttal: How Patchstack is improving WordPress security

Oliver's Twitter