Latest
Anthropic Bans Cruelty Toward Claude: What It Means for WritersWork-for-Hire Contracts: What the Asimov’s Cover Fight Teaches FreelancersGenre Fiction vs Literary Fiction: Don’t Confuse Taste With SkillFlorida Hurricane Prep Rituals: The Grocery Run, the Water Pallet and the Generator in the BoxThe Most Insulting Line of Dialogue Ever Written for the ScreenLoki Through the Ages: From Norse Myth to Marvel, The Mask and Dogma“You Are Utterly Disgusting”: A Book Festival, an AI Cover Ban and a Pile-OnWho Rewrote the Sligachan Legend: AI or the Tour Buses?Why I Don’t Like Reedsy for Ghostwriting: The NDA ProblemLayers: How I Ride Out Florida Power Outages in My ApartmentThe Enshittification of AmazonPublishers Cancel Books Over AI While Using It in SecretI Was Getting 100 Spam Emails a Day. $4.50 a Month Fixed It.World Mental Health Day: Nothing Was Wrong With MeKessler Syndrome: How Space Debris Could Close Earth’s OrbitAmazon Is Blocking Real Readers From Book ReviewsShould a Novella Get a Paperback, or Go Ebook Only?BookFunnel Download Problems: Fixes, Scams and AlternativesSir Sean Connery: A TributeHow to Find Plot Holes in Your Novel (Most Are Character Holes)Reshoring: The Factory Is the Easy PartMost of the Books I Was Forced to Read in High School Were CrapPlot Armor: Signs Your Hero Is Too Safe, and How to Fix ItShould You Sell Lifetime Rights to Your Self-Published Book for a Modest Advance?Shame Doesn’t Stop Artists From Using AI. It Stops Them From Telling You.AI Labels on TikTok and Meta Are Flagging Human WorkAuthor Richard Lowe Completes Peacekeeper, a Four-Book Science Fiction Series He Started at Age 14Sir Sam Neill: A TributeFan Art Copied by AI: Glass Houses, Copyright and the Pile-OnReal Names in a Book: Who Gets Sued, the Author, the Publisher or the Ghostwriter?When Characters Take Over the Plot, Let ThemDoes Human Writing Have a Soul?“You’re Not a Real Author”: The Pile-On Over AI-Assisted BooksDoes AI Have a Soul? Wrong QuestionHumor in Book Marketing: Getting Attention Without BeggingHow Long Should a Chapter Be? Manuscript Habits That Save You LaterThe Business Novel and the Companion Workbook: Two Formats Business Authors OverlookThe Back of the Book: Index, About the Author, Acknowledgments and Back Cover CopyI Build My Own Software Tools With Claude, and Some of Them Bit MeWhat Years of Buying From IT Vendors Taught MeI Write Books for a Living. I Barely Read Them Anymore.Three Management Habits That Waste Good PeopleThe Coach and the Webinar That Sold Me NothingThe Work I’d Cringe At Now, and Why I’m Glad I DoWho Is Your Book For? Build a Reader Avatar Before Chapter OnePreface, Prologue, Foreword or Introduction: What Goes WhereWhy I Won’t Build a Ghostwriting Business That ScalesHow I Hire a Virtual Assistant: Do It, Script It, Hand It OffThe Mail Carrier Who Thought Flipping Houses Was EasyWhat Wedding Photography Taught Me About Pricing Creative Work

WordPress Security Is a Posture, Not a Plugin

TL;DR: Security is a posture you hold, not a product you install, and plenty of compromised sites had a security plugin sitting green the whole time. Every article in this series was secretly about this: the theme nobody audits, the builder’s grip, the plugin count, the maintainer math, the supply chain they form. This closing piece names the posture outright and gives you the test for whether you have one.

Every article in this series has secretly been about security. The Frankenstein theme full of code nobody audits.

The page builder whose grip determines how fast you could respond to a crisis. The plugin diet that shrinks your attack surface with every removal. The maintainer count that predicts which of your update channels goes dark or changes hands. The supply chain those channels form. It was all one subject wearing different clothes, and this final article says the quiet part out loud.

Security is a posture, a set of habits you keep every day, and a product can only ever be one piece of it. That difference explains why so many compromised sites had a security plugin installed and dutifully green. Too many site owners trust that checkmark, because somebody sold it to them as the whole answer and they paid for it in good faith.

Can a security plugin make WordPress secure by itself?

The fantasy goes like this: install the right plugin, see the green checkmark, and security is handled, the way installing a contact form handles contact. It’s a comforting model, and the security industry happily sells to it, because products are billable and postures aren’t.

A security product is a component. It scans, it filters, it blocks known-bad patterns, and good ones do this well. What no product can do is make the decisions that determine your actual exposure: what you install, what you keep, who you trust upstream, whether anyone would notice a file that doesn’t belong, whether the backup restores.

Those are choices, made continuously, by a person. The plugin is a smoke detector. The posture isn’t storing gasoline in the living room.

My own incident, the one that started this series, makes the point cleanly. A scanner caught the payload the instant it landed, and I’m glad it did. But the scanner was only the last line. The defense was everything around it: knowing what belonged on the server so the alert meant something, having the incident traced instead of just deleted, and having already decided, years earlier, that something automated would always be watching. The product performed for thirty seconds. The posture had been performing for years.

What does a security posture look like?

Posture sounds abstract, so let me make it concrete with the practices that run on my own sites. None of this reveals anything an attacker can use, because none of it is secret. It’s just discipline, visible in outline and boring in execution. That’s what real security looks like.

Something watches, always. Automated scanning examines what lands on the server, because the attack that matters arrives dressed as something that belongs, and humans don’t catch that class of problem. Layers matter here: no single scanner sees everything, and the compromise my host caught might have slipped a different net. On my own sites, a major security plugin downloads new signatures every day, and my host quarantines anything executable that lands on the site before it can run.

Events leave records. Logins, changes, administrative actions: logged, timestamped, reviewable. When something odd happens, the difference between an afternoon and a catastrophe is whether you can reconstruct what occurred. An audit trail is the cheapest forensics you’ll ever buy, and you buy it before you need it or not at all. Late in 2024, a plugin on my site started alerting on break-in attempts, and I watched them in real time. They came over VPN from Russia, China and India with different usernames. It was obviously one person, because the attempts were seconds apart. They all failed. I’ve since moved the site behind Cloudflare.

When a small business site gets compromised, the first people hurt are its visitors: the prospect redirected to a scam page, the customer who types a card number into a form an attacker planted. They trusted the name on the site. An owner with no logs and no scanning finds out when one of those visitors complains, and by then that visitor’s trust is already spent.

The uninvited get less surface. Traffic from places I’ll never do business with doesn’t reach my sites. That removes a startling fraction of the automated hostility before any other defense has to think about it. Reducing who can even knock is arithmetic. I moved all 20 of my domains to Cloudflare after people tried to hack me, and the transfer took under ten minutes. Everything comes through Cloudflare’s front door now, and there’s no back door anymore. My pages also score 100 on Google PageSpeed every time, because Cloudflare caches every page.

Access is boring. Strong unique passwords, two-factor authentication, no shared accounts, admin access for the people who administer and nobody else. Nothing on this list is clever. Attackers don’t need you to be careless, but they profit a lot when you are.

I had Claude help me write my Cloudflare security rules. They’re complicated, and doing them alone would have taken me weeks, and I’d have gotten them wrong. Claude got them wrong too at first, but we fixed them. Cloudflare’s own streaming video product is expensive, so I don’t use it. I store almost 100GB of video there anyway, and it costs me well under a dollar a month.

Recovery is rehearsed. Backups exist, live off the server, and have been restored as a test. An untested backup is only a hope. This is the one practice that answers every failure mode at once, including the ones nobody has invented yet. And the stack stays small and known. Which returns to everything this series has argued: fewer components, chosen deliberately, from living projects, with exits priced in advance. A site you fully understand is a site where anomalies are visible. Complexity is where compromises hide.

That goes for code I write myself. I wrote an AEO plugin with Claude’s help, and then I had to run a security audit on it. It found a couple of security problems. Then I ran a performance audit, and that found a big performance problem. Now it’s really cool, and I’m having a blast. My site runs over 100 plugins now, and nearly all of them are ones I built.

What is the security posture test?

If you want to assess your own site, skip the plugin checklist and answer five questions, and don’t give yourself the benefit of the doubt on any of them.

Could you list everything running on your site right now, and would you notice an addition?

What would tell you something landed on your server at three in the morning? If your site started serving spam under your name today, how would you find out, and how long would it take? When did you last restore a backup, not make one, restore one? And who maintains each piece of software you depend on, and when did you last check?

Every one of those questions is about awareness and habit. You can’t answer a single one by purchasing anything. That’s the argument in miniature. Owners who answer these with the name of a product are the ones I worry about. If you can’t answer the backup question with a date, nobody knows whether your site would come back after an attack, and that includes you.

The beacon, kept lit

This series opened with a frame I want to close on. Your website is your beacon: the place your credibility lives, serving the handful of visitors who matter enormously. Everything in these seven articles, the theme surgery, the builder divorce, the plugin diet, the maintainer arithmetic, the supply chain vigilance, and finally this posture, is in service of that one asset, the trust those visitors place in you.

The work is unglamorous and continuous, and nobody selling you a plugin will say so. Security never ends.

You practice it the way you lock a door every night, without ceremony. Practice it yourself with the questions above, or hand the practice to someone who has done it for decades. Either way, keep the beacon lit. The people it was built for are watching it to decide about you.

Security doesn’t end, it’s simply practiced, the way you lock a door every night without ceremony.
Share on X

Frequently Asked Questions

Why isn’t a security plugin enough to protect WordPress?
Because plenty of compromised sites had one installed and glowing green. A plugin watches for known attacks; it can’t shrink your attack surface, vet your vendors, or decide what runs on your site. Those are decisions, and decisions are a posture.
What is a security posture for a website?
The sum of your standing decisions: what you install, whom you trust, what you remove, how updates flow, and what you check on a schedule. A product is something you buy once. A posture is something you hold continuously.
What does a good WordPress security posture include?
A solid WordPress security posture rests on the practices I run on my own sites. I keep something watching the server at all times, because automated scanning catches the attack that arrives dressed as something that belongs, and humans miss that class of problem. I log every login, change, and administrative action so I can reconstruct what happened if something goes wrong. I block traffic from places I’ll never do business with, require strong unique passwords and two-factor authentication, and limit admin access to the people who administer. I rehearse recovery by restoring backups instead of just making them, and I keep my plugin stack small and chosen deliberately so anomalies stay visible.
How do you test your website’s security posture?
Ask what would happen if each trusted channel turned hostile tomorrow: a plugin sold, a theme abandoned, an update poisoned. If the answer is a shrug, the green checkmark is theater. If you have an answer per channel, you have a posture.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment