Podcast: Play in new window | Download | Embed
The Weeks Discussions:
Katie from Barn 2 starts a great discussions
sources:
-
Katie’s post: x.com/KatieKeithBarn2/status/2093594168643756115
-
Barn2 2025 Year in Review: barn2.com/blog/2025-year-in-review
-
Earlier strategy interview: insider.thewpgirls.com — Beyond WordPress / Barn2 2025 goals
Katie Keith did not post a manifesto. She posted a status check. On 29 August she pointed at WP Builds 482, where Nathan Wrigley and Sé Reed called a lot of WordPress companies a holding pattern: not walking out, not pouring new money in, waiting for the ground to stop moving. Then she said that is Barn2. Stay on the existing WordPress plugins. Make the popular ones better. Put the new product work somewhere else. She did not pretend it was a tidy strategy. She called the moment strange and unprecedented.
The episode behind that line is the useful part. Sé’s picture was an airport that will not clear: the trademark fight is pushed toward October 2027, nobody is publishing a “we’re done with WordPress” post, and sponsorships and big bets go quiet because not-knowing freezes people. Katie put a real shop under that weather report. Barn2 still does about $1.7M a year in WordPress plugins. Renewals carried 2025. New sales fell hard. Ninety-seven plugin updates shipped. The first Shopify app went out anyway. The quiet work is the renewals, the refactors, the support queue. The expansion chips are no longer automatic “another WordPress plugin.”
That is why it belongs under The Quiet Work That Keeps WordPress Alive. Katie is not saying the platform is finished. She is saying a mature plugin company can keep the installed base alive and still refuse to bet the next catalog on one courtroom calendar and one broken discovery channel. Holding pattern from the outside. Maintenance plus diversification from the inside. Whether that keeps WordPress alive, or just keeps shops like Barn2 alive until 2027, is the question for the episode.
WordPress Drama:
Rank Math puts thier foot in it
Roger Montti’s 31 August SEJ item is the public stamp on a fight that started three days earlier. Rank Math 1.0.277 shipped on 26 August with a “[HUGE!]” Support Agent in Help & Support. Same release patched about a dozen security holes. Sybre Waaijer of The SEO Framework then posted the part Rank Math did not advertise: on a site tied to a free Rank Math account, opening Help & Support minted a WordPress Application Password for whoever was logged in and sent it to group.one’s servers before the terms box even showed. Name on the profile: WAP – Rank Math Support Agent. No expiry. Closing the tab did not revoke it. You could not turn the agent off. Application Passwords have no capability scopes, so an admin session meant admin powers on a plugin that sits on four million sites. Parent company is group.one. Same house as WP Rocket.
Rank Math paused it in 1.0.277.2 on 31 August, the day Montti wrote it up. Their line: consent was not explicit enough, credentials were encrypted and not stored on their side, the agent inherited the current user’s role and was read-only, and the agent will come back with plain-language permission first. Follow-ups did not buy the cleanup as a full answer. The public changelog talked about pausing the agent. The code had a one-shot function that only deletes passwords with that exact name. Critics said “encrypted” still means group.one can read it, or the agent is useless. Sybre said they still had not answered the real charge: the password left the site before anyone accepted terms. On Montti’s post the replies were short and ugly. “So sketchy.” “Companies like this are bad for the eco-system’s reputation as a whole.”
Then Matt piled on in the plugin review Slack. Admin and management plugins should pass an infrastructure security audit. He named Rank Math and Awesome Motive as recently hacked and called unaudited admin/update hooks “more a back door than a service.” Practical note for the show: if anyone opened Help & Support on 1.0.277 while connected, they still need to check Users → Profile → Application Passwords and revoke anything starting WAP –. The quiet work here is not the AI chatbot. It is whether a four-million-site SEO plugin can mint a remote login without a real yes, then call the pause a communication problem.
Mullenweg put on leave https://www.reddit.com/r/WPDrama/comments/1wbyxcm/automattic_ceo_matt_mullenweg_put_on_leave_of/
On 9 September the Automattic board put Matt Mullenweg on a paid leave of absence and named CFO Mark Davies interim CEO. Matt did not resign. He lost a vote. He told staff in company Slack that Davies had “conspired” with directors Ann Dunwoody, Toni Schneider, and Sue Decker “behind my back.” He said the resolution landed 50 minutes before the meeting, he asked for a few hours with independent counsel, and that was denied. He voted no. The company statement was colder: Matt is on leave, the board has full confidence in Mark. Schneider, who ran Automattic from 2006 to 2014, told staff they asked Matt to step away from the CEO seat while he is out. Davies told the room Matt stays on the board and still has a voice. Nobody published a reason.
404 Media broke it. The Verge and WP More pushed it into the feed the same night. r/WPDrama did what that sub does and turned the leak into a thread. The next morning Matt was on X asking for sysadmins and security researchers “really quick,” nobody from Automattic, because he wants some of his own stuff moved off Automattic hosting. Same thread: he will not repeat the 2024 private-equity mistake, then pointed at his own old posts about Silver Lake, disappearing Signal messages, and a tip line he now says was illegal once a preservation order existed. He says he still supports Mark as interim CEO. The tone is not a quiet exit. It is a founder who just lost the operating keys and is talking in public anyway.
The split that matters for WordPress is the one Mary Hubbard had to post. Automattic changed CEOs. WordPress.org did not. Hubbard told the project Matt remains leader, she remains executive director, 7.1 work continues. Matt quoted her and said he set WordPress up to survive this exact scenario. That is the legal architecture talking: he still owns the .org infrastructure personally, he still sits on Automattic’s board, and the Foundation still holds the marks while Automattic holds the commercial license. The company that sells hosting and Woo can swap a CEO. The distribution pipe millions of sites still use did not change hands on Wednesday.
Context the board did not put in the press line: the WP Engine suit is still live, a sanctions fight over missing messages and lost devices is on the calendar for 30 September, BlackRock’s last mark implies Automattic is worth a fraction of the 2021 $7.5B round, and Matt has said he holds most of the voting power. So this is not “founder retires to the beach.” It is the commercial company putting the founder on ice while the founder still runs the open-source side and still has a board seat. For Plugin Pulse that is the story. The quiet work of plugins and sites now sits under a company with an interim CFO-CEO and a project still steered by the man the board just benched. Whether that calms the holding pattern or makes it worse is the live question.
Security Stuff:
White Screen or a Hack recovery Choose wisely
WordPress just admitted the old security pace is dead. On 28 August Rudy Faile posted the Core Security Initiative on the Making WordPress Secure blog: a formal ABC plan after a year of incoming reports the team can no longer treat as a side queue. A is a tighter, more automated release process with better end-to-end testing. B is more people on the backlog until open findings hit zero. C is crush vulnerabilities with AI-assisted scanning before somebody else does. The Repository’s 1 September write-up is the public version of that post. The X card is the same story in one line: a 15x spike in reports and an unprecedented run of core security releases.
The numbers are the reason they had to name it. HackerOne sat at 20 to 30 reports a month for about a decade. July hit 450. August hit 773. John Blackbourn called it a new era of AI-assisted research. The jump started in January and February off GPT 5.3 and Claude Opus 4.6 and then did not slow down. Mixed in that pile: valid bugs, duplicates, and slop from models that lock onto one issue and file it ten times. Summer already proved the cost. 7.0.2 on 17 July patched a critical pre-auth RCE found with OpenAI’s Sol Ultra in about ten hours. 7.0.3 three weeks later fixed twelve issues. 7.0.4 a week after that patched an author-level Imagick RCE. Then the bounty program itself had to shrink. Low-severity role-confusion reports are largely out of scope now except on Core and Gutenberg. More eyes, Faile said, make WordPress safer. They also bury the team unless the process changes.
That is the official story. The show take is what you do on a real site while that machine spins up. Core can ship three emergency releases in a month. Most sites still wait for a human to click Update. Plugins and themes are where the volume actually lives, and AI is chewing those faster than volunteer review ever will. Automatic updates used to be the thing agencies turned off because a bad plugin could white-screen the homepage on a Friday. That fear is still real. It is also the wrong comparison in 2026. A white screen is a known failure. You roll back, you disable the plugin, you are back. A good hack is quiet. It is a new admin user, a mailer in mu-plugins, a stolen Woo list, a backdoor that survives the “restore from last week” you thought was clean. One afternoon of recovery beats six months of not knowing you were owned.
So the speculative push for Episode 21 is simple. Lean into auto-updates for Core, and get braver on trusted plugins, because the patch window is now measured in hours and the scanners on the other side do not sleep. Keep a staging site. Keep updrafts that actually restore. Turn on auto-updates where the vendor is not a stranger. Accept that you will eat a broken update once in a while. That is the cheaper outage. The Core Security Initiative is the project trying to keep up with AI. Automatic updates are how a shop keeps up with the Initiative. A white screen is a bad afternoon. A quiet compromise is a bad year.
Report of vulnerabilities are rising
This is the same fire as the Core Security Initiative, one day later, with the valve actually turned. On 2 September The Repository posted that WordPress’s HackerOne queue went from a decade of 20–30 reports a month to 450 in July and 773 in August. John Blackbourn said the quiet part in Post Status Slack: unmanageable low-severity volume meant the program had to change what it will accept. Automattic’s Ehtisham Siddiqui put the new rules on the Making WordPress Secure blog the same day. The X card is that story in one sentence. The Initiative was the strategy post. This is the triage post.
What got cut is the AI slop that was drowning real bugs. For everything in scope except Core and Gutenberg, a finding that needs a role only an administrator can hand out — Contributor included — is generally out unless it is a high-severity escalation with real impact. Same for “this authenticated role can do a thing that another authenticated role can already do.” That used to be a valid report. Now it is noise unless it jumps the fence. Researchers are pointed at unauthenticated bugs and Subscriber-level punches. Core and Gutenberg keep the old eligibility rules for now, which tells you where the team still wants every scrap of signal. The program is not closed. It is on a diet.
Read it against Friday’s Initiative and the sequence is obvious. Rudy Faile’s ABC plan said scale the release process, staff the backlog, and use AI to find bugs before the bounty inbox does. Four days later they had to shrink the inbox so A, B, and C can exist. 773 reports is not 773 RCEs. It is models filing the same medium issue until the humans cannot see the pre-auth hole in 7.0.2. The Initiative is offense and capacity. The scope change is defense of the security team’s calendar. One does not work without the other.
For the show, that is the site-security beat continuing, not a new drama. More reports does not mean every site is more doomed tomorrow. It means patches will keep coming in bunches, a lot of “bugs” will never be bounty-eligible, and waiting to click Update by hand gets dumber every month. Core is still taking the kitchen-sink reports. Plugins, official apps, and .org infra are not. If you only remember one line: they did not tighten the bounty because WordPress got safer. They tightened it because the firehose made the old definition of “a report” unusable.
Elementor security check yours
Wordfence’s 2 September reminder is the live proof of the auto-update argument. CVE-2026-32475 is an unauthenticated arbitrary file upload in Elementor Pro through 4.2.1: if a published form has a File Upload field, a stranger can slip a PHP file past validation and land a webshell in /wp-content/uploads/elementor/forms/. Six million installs. Patched in 4.2.2 on 19 August. Attackers started the same day. Wordfence had already blocked more than 190,000 attempts by the time they posted. That is not a theoretical Core Security Initiative chart. That is a premium builder most agencies ship on client sites, a nine-point-eight hole, and a two-week window where “I’ll update Friday” was the difference between a white screen you roll back and a PHP file you never noticed. If Elementor Pro is not on 4.2.2 or later, stop the show notes and patch it. Then look in that forms upload folder for anything ending in .php.
Educational:
New type malware being tracked
The Reddit thread is the street version of a class of infection that security shops have been writing up all year: you delete the bad files, reload the site, and they are back. That is not a sloppy cleanup. That is the design. Older WordPress malware lived in a file. You found the file, you killed the file. The new wave stores the real payload in the database — usually a pile of encrypted rows in wp_options with junk names — and treats everything on disk as disposable scaffolding. Delete the scaffolding and the next request rebuilds it. Sometimes in seconds. Sometimes the scanner and the malware just fight each other until the CPU is on fire and nobody has actually won.
Researchers have been mapping the same family under different labels. In May and June, writeups described a dual-layer backdoor: a file on disk plus a copy in the database that rewrites the file on every hit. Monarx flagged a campaign that used a fake wp-cron plus a six-minute integrity checker that re-downloaded missing pieces from a command server. By late August, MD Pabel documented SC 4.0.3 hiding as a fake plugin called Trace Scanner Lite, cloned into mu-plugins, drop-ins like db.php and advanced-cache.php, a .user.ini prepend, theme functions.php, and zip files sitting in uploads as cold storage. On 8 September Konstantinos Bourdakos published the ugliest version yet: ten incident-response cases, 1,200-plus sites, fifteen independent persistence layers, self-upgrades that rename files so signatures rot, and newer builds taking orders off a public blockchain so there is no domain to seize. Shared hosting makes it worse. One dirty account reads sibling wp-config.php files and walks the rest of the box.
Cleanup that only touches wp-content/plugins is theatre. Must-use plugins do not show on the Plugins screen and load before Wordfence. Drop-ins load if WP_CACHE is on. auto_prepend_file runs before WordPress exists. A fake name in the active_plugins option makes core itself bootstrap the junk on every request. Hidden admins, stolen cookies, and a service worker in the admin browser can put the infection back even after the server looks clean. The practical sequence from the people who have actually killed this: take the site offline, kill crons and stray PHP processes, clean the database with real PHP serialize tools not a blind SQL replace, delete the file mesh in one pass, drop unexpected MySQL triggers, rotate every password and key, then check every other WordPress install under the same user. A dashboard scan that says “0 issues” is not that sequence.
This is why the auto-update argument from the Core Security Initiative still holds, and why it is not enough. A white-screen plugin update is a bad afternoon. This family is what you get when the afternoon never happens and the hole stays open. Patch Elementor Pro, patch Core, turn on updates so the front door closes faster. Then assume a “clean” scan after a hack is a lie until someone has looked at mu-plugins, drop-ins, .user.ini, wp_options, and sibling sites. The new wave is not louder malware. It is malware that treats your cleanup as a scheduled task.
Tip of The Day:
Satirical game on the realities of running a plugin business [FREE]
Link straight to the Game https://pressword.games/games/install-clicker/
Warning it mildly addictive…





