WPPlugins AtoZ

Powered by WPPro AtoZ Host

Plugin Pulse 21: -The Quiet Work That Keeps WordPress Alive

0:00 / 0:00
Plugin Pulse 21: -The Quiet Work That Keeps WordPress Alive

Donate to the Show


cards
Powered by paypal

Watch The Video

TLDR Summary of Show

Episode 21 sits on one idea: WordPress is still standing because of unglamorous work, not because the week was calm. Katie Keith put a product P&L on the “holding pattern” line from WP Builds 482 — keep the plugins people already pay for, put new product somewhere the ground is less shaky. That is the quiet work on the business side. The security side is louder and worse. Rank Math’s Support Agent minted admin-level application passwords and sent them to group.one before the terms box even appeared, then paused the feature and promised it back with clearer consent. Core admitted the old security pace is dead: HackerOne went from 20–30 reports a month to 450 in July and 773 in August, the Core Security Initiative got a name, and the bounty program had to shrink so humans can still see real holes. Elementor Pro’s critical file-upload bug was under active exploit the day it was disclosed. Self-healing malware now lives in the database and rebuilds the files you just deleted.
Over all of that, Automattic’s board put Matt Mullenweg on paid leave and named CFO Mark Davies interim CEO. Matt stays on the board and still leads the WordPress project. Mary Hubbard said .org does not change. The commercial company and the open-source pipe are not the same machine this week, which is exactly why shops are rationing courage. A white-screen plugin update is a bad afternoon. A quiet compromise, a remote login you did not grant, or malware that treats your cleanup as a scheduled task is a bad year. The work that keeps WordPress alive right now is renewals, patches, auto-updates, and people who still maintain what is already installed.

This Shows Featured Promotion

Toggle WP

The Lowdown:
How ToggleWP Helps
  • On-Brand AI Upsells: Deploy a high-end AI writing assistant directly in the client dashboard, allowing you to charge a premium for “AI-Enhanced” maintenance tiers.
  • Zero-Cost Fulfillment (BYOK): Use your own API key to provide advanced content tools with no monthly markup, keeping 100% of the profit from your client subscriptions.
  • Done-With-You Content: Reduce the time spent drafting blogs or social snippets for clients by 80%, increasing your hourly effective rate.
  • Feature Lock-In: Create a “sticky” workspace that makes it nearly impossible for clients to leave your care for a budget host that lacks these tools.

The Maintenance-Focused Freelancer

How ToggleWP Helps
  • Plugin Control: Hide essential plugins from client admins (so they can’t accidentally deactivate your security or backup plugins, or enable auto updates)
  • Plugin Activation / Deactivation Notifications: Get instant alerts when clients make plugin changes
  • SEO Warnings: Visual warnings prevent “oops” moments like blocking indexing on a production site
  • Staging Site Warning: Remind clients not to update live site content while you are working on staging with notices on the login screen / after login
  • Reminders: Track renewal dates for domains, annual subscriptions or premium licenses with email notifications before expiry

The Boutique Hosting Provider

How ToggleWP Helps
  • Login Monitoring: Track admin logins with IP/country detection, spot suspicious access patterns across your portfolio
  • Admin Notifications: Automated email system sends you monthly last login reports and instant alerts for unusual logins
  • Session Management: Force logout inactive sessions, limit admin user sessions to 1 hour
  • Media Management: Clients can organise their media uploads with custom categories and tags, allowing easy filtering from the Insert Media screen
  • Reminders: Track renewal dates for domains, annual subscriptions or premium licenses with email notifications before expiry

Full Show Notes

The Weeks Discussions:

Katie from Barn 2 starts a great discussions
sources:
  1. Barn2 2025 Year in Review: barn2.com/blog/2025-year-in-review
Katie Keith did not post a manifesto. She posted a status check. On 29 August she pointed at WP Builds 482, where Nathan Wrigley and Sé Reed called a lot of WordPress companies a holding pattern: not walking out, not pouring new money in, waiting for the ground to stop moving. Then she said that is Barn2. Stay on the existing WordPress plugins. Make the popular ones better. Put the new product work somewhere else. She did not pretend it was a tidy strategy. She called the moment strange and unprecedented.
The episode behind that line is the useful part. Sé’s picture was an airport that will not clear: the trademark fight is pushed toward October 2027, nobody is publishing a “we’re done with WordPress” post, and sponsorships and big bets go quiet because not-knowing freezes people. Katie put a real shop under that weather report. Barn2 still does about $1.7M a year in WordPress plugins. Renewals carried 2025. New sales fell hard. Ninety-seven plugin updates shipped. The first Shopify app went out anyway. The quiet work is the renewals, the refactors, the support queue. The expansion chips are no longer automatic “another WordPress plugin.”
That is why it belongs under The Quiet Work That Keeps WordPress Alive. Katie is not saying the platform is finished. She is saying a mature plugin company can keep the installed base alive and still refuse to bet the next catalog on one courtroom calendar and one broken discovery channel. Holding pattern from the outside. Maintenance plus diversification from the inside. Whether that keeps WordPress alive, or just keeps shops like Barn2 alive until 2027, is the question for the episode.

WordPress Drama:

Rank Math puts thier foot in it
Roger Montti’s 31 August SEJ item is the public stamp on a fight that started three days earlier. Rank Math 1.0.277 shipped on 26 August with a “[HUGE!]” Support Agent in Help & Support. Same release patched about a dozen security holes. Sybre Waaijer of The SEO Framework then posted the part Rank Math did not advertise: on a site tied to a free Rank Math account, opening Help & Support minted a WordPress Application Password for whoever was logged in and sent it to group.one’s servers before the terms box even showed. Name on the profile: WAP – Rank Math Support Agent. No expiry. Closing the tab did not revoke it. You could not turn the agent off. Application Passwords have no capability scopes, so an admin session meant admin powers on a plugin that sits on four million sites. Parent company is group.one. Same house as WP Rocket.
Rank Math paused it in 1.0.277.2 on 31 August, the day Montti wrote it up. Their line: consent was not explicit enough, credentials were encrypted and not stored on their side, the agent inherited the current user’s role and was read-only, and the agent will come back with plain-language permission first. Follow-ups did not buy the cleanup as a full answer. The public changelog talked about pausing the agent. The code had a one-shot function that only deletes passwords with that exact name. Critics said “encrypted” still means group.one can read it, or the agent is useless. Sybre said they still had not answered the real charge: the password left the site before anyone accepted terms. On Montti’s post the replies were short and ugly. “So sketchy.” “Companies like this are bad for the eco-system’s reputation as a whole.”
Then Matt piled on in the plugin review Slack. Admin and management plugins should pass an infrastructure security audit. He named Rank Math and Awesome Motive as recently hacked and called unaudited admin/update hooks “more a back door than a service.” Practical note for the show: if anyone opened Help & Support on 1.0.277 while connected, they still need to check Users → Profile → Application Passwords and revoke anything starting WAP –. The quiet work here is not the AI chatbot. It is whether a four-million-site SEO plugin can mint a remote login without a real yes, then call the pause a communication problem.
On 9 September the Automattic board put Matt Mullenweg on a paid leave of absence and named CFO Mark Davies interim CEO. Matt did not resign. He lost a vote. He told staff in company Slack that Davies had “conspired” with directors Ann Dunwoody, Toni Schneider, and Sue Decker “behind my back.” He said the resolution landed 50 minutes before the meeting, he asked for a few hours with independent counsel, and that was denied. He voted no. The company statement was colder: Matt is on leave, the board has full confidence in Mark. Schneider, who ran Automattic from 2006 to 2014, told staff they asked Matt to step away from the CEO seat while he is out. Davies told the room Matt stays on the board and still has a voice. Nobody published a reason.
404 Media broke it. The Verge and WP More pushed it into the feed the same night. r/WPDrama did what that sub does and turned the leak into a thread. The next morning Matt was on X asking for sysadmins and security researchers “really quick,” nobody from Automattic, because he wants some of his own stuff moved off Automattic hosting. Same thread: he will not repeat the 2024 private-equity mistake, then pointed at his own old posts about Silver Lake, disappearing Signal messages, and a tip line he now says was illegal once a preservation order existed. He says he still supports Mark as interim CEO. The tone is not a quiet exit. It is a founder who just lost the operating keys and is talking in public anyway.
The split that matters for WordPress is the one Mary Hubbard had to post. Automattic changed CEOs. WordPress.org did not. Hubbard told the project Matt remains leader, she remains executive director, 7.1 work continues. Matt quoted her and said he set WordPress up to survive this exact scenario. That is the legal architecture talking: he still owns the .org infrastructure personally, he still sits on Automattic’s board, and the Foundation still holds the marks while Automattic holds the commercial license. The company that sells hosting and Woo can swap a CEO. The distribution pipe millions of sites still use did not change hands on Wednesday.
Context the board did not put in the press line: the WP Engine suit is still live, a sanctions fight over missing messages and lost devices is on the calendar for 30 September, BlackRock’s last mark implies Automattic is worth a fraction of the 2021 $7.5B round, and Matt has said he holds most of the voting power. So this is not “founder retires to the beach.” It is the commercial company putting the founder on ice while the founder still runs the open-source side and still has a board seat. For Plugin Pulse that is the story. The quiet work of plugins and sites now sits under a company with an interim CFO-CEO and a project still steered by the man the board just benched. Whether that calms the holding pattern or makes it worse is the live question.

Security Stuff:

White Screen or a Hack recovery Choose wisely
WordPress just admitted the old security pace is dead. On 28 August Rudy Faile posted the Core Security Initiative on the Making WordPress Secure blog: a formal ABC plan after a year of incoming reports the team can no longer treat as a side queue. A is a tighter, more automated release process with better end-to-end testing. B is more people on the backlog until open findings hit zero. C is crush vulnerabilities with AI-assisted scanning before somebody else does. The Repository’s 1 September write-up is the public version of that post. The X card is the same story in one line: a 15x spike in reports and an unprecedented run of core security releases.
The numbers are the reason they had to name it. HackerOne sat at 20 to 30 reports a month for about a decade. July hit 450. August hit 773. John Blackbourn called it a new era of AI-assisted research. The jump started in January and February off GPT 5.3 and Claude Opus 4.6 and then did not slow down. Mixed in that pile: valid bugs, duplicates, and slop from models that lock onto one issue and file it ten times. Summer already proved the cost. 7.0.2 on 17 July patched a critical pre-auth RCE found with OpenAI’s Sol Ultra in about ten hours. 7.0.3 three weeks later fixed twelve issues. 7.0.4 a week after that patched an author-level Imagick RCE. Then the bounty program itself had to shrink. Low-severity role-confusion reports are largely out of scope now except on Core and Gutenberg. More eyes, Faile said, make WordPress safer. They also bury the team unless the process changes.
That is the official story. The show take is what you do on a real site while that machine spins up. Core can ship three emergency releases in a month. Most sites still wait for a human to click Update. Plugins and themes are where the volume actually lives, and AI is chewing those faster than volunteer review ever will. Automatic updates used to be the thing agencies turned off because a bad plugin could white-screen the homepage on a Friday. That fear is still real. It is also the wrong comparison in 2026. A white screen is a known failure. You roll back, you disable the plugin, you are back. A good hack is quiet. It is a new admin user, a mailer in mu-plugins, a stolen Woo list, a backdoor that survives the “restore from last week” you thought was clean. One afternoon of recovery beats six months of not knowing you were owned.
So the speculative push for Episode 21 is simple. Lean into auto-updates for Core, and get braver on trusted plugins, because the patch window is now measured in hours and the scanners on the other side do not sleep. Keep a staging site. Keep updrafts that actually restore. Turn on auto-updates where the vendor is not a stranger. Accept that you will eat a broken update once in a while. That is the cheaper outage. The Core Security Initiative is the project trying to keep up with AI. Automatic updates are how a shop keeps up with the Initiative. A white screen is a bad afternoon. A quiet compromise is a bad year.
Report of vulnerabilities are rising
This is the same fire as the Core Security Initiative, one day later, with the valve actually turned. On 2 September The Repository posted that WordPress’s HackerOne queue went from a decade of 20–30 reports a month to 450 in July and 773 in August. John Blackbourn said the quiet part in Post Status Slack: unmanageable low-severity volume meant the program had to change what it will accept. Automattic’s Ehtisham Siddiqui put the new rules on the Making WordPress Secure blog the same day. The X card is that story in one sentence. The Initiative was the strategy post. This is the triage post.
What got cut is the AI slop that was drowning real bugs. For everything in scope except Core and Gutenberg, a finding that needs a role only an administrator can hand out — Contributor included — is generally out unless it is a high-severity escalation with real impact. Same for “this authenticated role can do a thing that another authenticated role can already do.” That used to be a valid report. Now it is noise unless it jumps the fence. Researchers are pointed at unauthenticated bugs and Subscriber-level punches. Core and Gutenberg keep the old eligibility rules for now, which tells you where the team still wants every scrap of signal. The program is not closed. It is on a diet.
Read it against Friday’s Initiative and the sequence is obvious. Rudy Faile’s ABC plan said scale the release process, staff the backlog, and use AI to find bugs before the bounty inbox does. Four days later they had to shrink the inbox so A, B, and C can exist. 773 reports is not 773 RCEs. It is models filing the same medium issue until the humans cannot see the pre-auth hole in 7.0.2. The Initiative is offense and capacity. The scope change is defense of the security team’s calendar. One does not work without the other.
For the show, that is the site-security beat continuing, not a new drama. More reports does not mean every site is more doomed tomorrow. It means patches will keep coming in bunches, a lot of “bugs” will never be bounty-eligible, and waiting to click Update by hand gets dumber every month. Core is still taking the kitchen-sink reports. Plugins, official apps, and .org infra are not. If you only remember one line: they did not tighten the bounty because WordPress got safer. They tightened it because the firehose made the old definition of “a report” unusable.
Elementor security check yours
Wordfence’s 2 September reminder is the live proof of the auto-update argument. CVE-2026-32475 is an unauthenticated arbitrary file upload in Elementor Pro through 4.2.1: if a published form has a File Upload field, a stranger can slip a PHP file past validation and land a webshell in /wp-content/uploads/elementor/forms/. Six million installs. Patched in 4.2.2 on 19 August. Attackers started the same day. Wordfence had already blocked more than 190,000 attempts by the time they posted. That is not a theoretical Core Security Initiative chart. That is a premium builder most agencies ship on client sites, a nine-point-eight hole, and a two-week window where “I’ll update Friday” was the difference between a white screen you roll back and a PHP file you never noticed. If Elementor Pro is not on 4.2.2 or later, stop the show notes and patch it. Then look in that forms upload folder for anything ending in .php.

Educational:

New type malware being tracked
The Reddit thread is the street version of a class of infection that security shops have been writing up all year: you delete the bad files, reload the site, and they are back. That is not a sloppy cleanup. That is the design. Older WordPress malware lived in a file. You found the file, you killed the file. The new wave stores the real payload in the database — usually a pile of encrypted rows in wp_options with junk names — and treats everything on disk as disposable scaffolding. Delete the scaffolding and the next request rebuilds it. Sometimes in seconds. Sometimes the scanner and the malware just fight each other until the CPU is on fire and nobody has actually won.
Researchers have been mapping the same family under different labels. In May and June, writeups described a dual-layer backdoor: a file on disk plus a copy in the database that rewrites the file on every hit. Monarx flagged a campaign that used a fake wp-cron plus a six-minute integrity checker that re-downloaded missing pieces from a command server. By late August, MD Pabel documented SC 4.0.3 hiding as a fake plugin called Trace Scanner Lite, cloned into mu-plugins, drop-ins like db.php and advanced-cache.php, a .user.ini prepend, theme functions.php, and zip files sitting in uploads as cold storage. On 8 September Konstantinos Bourdakos published the ugliest version yet: ten incident-response cases, 1,200-plus sites, fifteen independent persistence layers, self-upgrades that rename files so signatures rot, and newer builds taking orders off a public blockchain so there is no domain to seize. Shared hosting makes it worse. One dirty account reads sibling wp-config.php files and walks the rest of the box.
Cleanup that only touches wp-content/plugins is theatre. Must-use plugins do not show on the Plugins screen and load before Wordfence. Drop-ins load if WP_CACHE is on. auto_prepend_file runs before WordPress exists. A fake name in the active_plugins option makes core itself bootstrap the junk on every request. Hidden admins, stolen cookies, and a service worker in the admin browser can put the infection back even after the server looks clean. The practical sequence from the people who have actually killed this: take the site offline, kill crons and stray PHP processes, clean the database with real PHP serialize tools not a blind SQL replace, delete the file mesh in one pass, drop unexpected MySQL triggers, rotate every password and key, then check every other WordPress install under the same user. A dashboard scan that says “0 issues” is not that sequence.
This is why the auto-update argument from the Core Security Initiative still holds, and why it is not enough. A white-screen plugin update is a bad afternoon. This family is what you get when the afternoon never happens and the hole stays open. Patch Elementor Pro, patch Core, turn on updates so the front door closes faster. Then assume a “clean” scan after a hack is a lie until someone has looked at mu-plugins, drop-ins, .user.ini, wp_options, and sibling sites. The new wave is not louder malware. It is malware that treats your cleanup as a scheduled task.

Tip of The Day:

Satirical game on the realities of running a plugin business [FREE]
Warning it mildly addictive…

Table of Contents

Affiliate Links
  • Termageddon Use Termageddon to help comply with privacy laws such as the CPRA, GDPR, UK DPA, CalOPPA, PIPEDA, and more. They will also help you comply with consumer protection laws, provide eCommerce disclosures, and limit your liability. Click on our link here!
    Termageddon
  • Rank Math Rank Math is a fantastic company to work with on your sites SEO. The Free version will give you everything you need to get started and get your SEO up to a place where you will get noticed! The Premium version is like getting VIP Treatment when it comes to the tools available. The documentation they have available is in easy to read, every day language so that it does not require a degree to understand how to use the tools!
    Rank Math
  • Bunny.net Quick easy CDN that is affordable. Great prices, easy to use! Click on our link here!
    Bunny.net
  • Glow WP Maintenance Manager Use coupon code WPPAZ10 10% discount on their subscription, for life.
    Glow WP Maintenance Manager

Your Hosts

John Overall

Over 16 years a counting for WP Plugins A to Z more about John click this.

Amber Linn

Since 2020 Amber has been making WP Plugins A to Z the place to be more about Amber click this.

Highlighted Links
Categories
Archives

Book an Interview on WPPluginsAtoZ

If You're a Plugin/Theme Developer or WP Community Member

Book your interview now.