-

·
You can’t observe a security backport by waiting for one
Security backports arrive when they arrive, and between releases there’s nothing to watch. So I built a small harness that fakes one field in WordPress.org’s update offer and lets a real release install through core’s own upgrader, with a self-test for the failures that look like success.
-

·
Why I retired my own security plugin
Sudo was a plugin that asked WordPress administrators for their password before they did something dangerous. An AI audit found seven ways around it with an active admin session. That points to a fundamental architectural problem that only WordPress core can address.