Home Blog WordPress Podcast How Enterprises and Businesses Approach WordPress Security with Dan Knauss

How Enterprises and Businesses Approach WordPress Security with Dan Knauss

Click to accept marketing cookies and enable this content
Spinner

In This Episode

In this episode, we spoke with Dan Knauss about WordPress security in enterprise environments. The conversation focused on what companies actually worry about when using WordPress and how security decisions are made in real projects.

We also explored the gap between security noise and practical risk. From user access and governance to the value of long-term maintenance, this episode makes the case that trust, visibility, and clear communication matter far more than fear-driven messaging.

All Episode Links

Key Takeaways

  • Enterprise teams care about trust and stability

Many enterprise teams are already comfortable with WordPress. They know the platform, understand its capabilities, and, in many cases, are already using it successfully in some part of the business. That means the conversation rarely starts with WordPress having to prove itself from scratch.

The real work begins when deeper technical stakeholders get involved. At that stage, the discussion shifts toward integration, governance, risk, and long-term support. Trust matters a lot here, and it’s built through clear explanations, realistic planning, and confidence that WordPress can fit into a broader business and technical environment.

  • Security problems often come from poor access management

One of the strongest topics in the conversation is that WordPress security problems are often less about WordPress itself and more about user management. Broken access controls, stale permissions, phishing, and weak oversight create far more risk than many of the headlines people react to.

That is why visibility matters so much. Teams need to know who has access, what they are doing, whether permissions are still appropriate, and how quickly suspicious activity can be spotted and contained. In practice, many security issues stem from avoidable human mistakes rather than failures in the platform itself.

  • Long-term maintenance beats panic and hype

WordPress is a mature platform that many large organizations use successfully, and that maturity matters. It means the platform has been tested at scale, refined over time, and supported by a broad ecosystem of agencies, hosts, developers, and product teams.

The conversation also highlights how easy it is to get distracted by hype, especially when new tools or platforms are positioned as the next big replacement. But long-term success usually comes from regular updates, clear processes, responsible security practices, and steady maintenance rather than reacting emotionally to every new trend or fear-driven narrative.

About the Host 

Robert Abela is the founder and CEO of Melapress, where he leads the company’s strategy and ensures the team has the direction and support needed to deliver high-quality WordPress security and management tools.

With more than 23 years of experience in IT and software, Robert hosts The Melapress Show, a weekly live show every Thursday at 16:00 CET (10:00 a.m. ET), featuring Q&A sessions, expert interviews, and practical discussions focused on WordPress security, user management, compliance, and more.

About the Guest

Dan Knauss has worked as a solution architect with an enterprise WordPress agency and as a technical generalist on a WordPress product team. He also ran an open-source consultancy for more than a decade and has spent years working across technical, editorial, and team-facing roles.

His background also includes teaching university students how to build clarity and confidence through writing, speaking, and team-building. Follow Dan Knauss on LinkedIn and discover more on his personal website.

Episode transcript

Robert Abela: Hello, thank you for joining this episode of the Melapress Show today. This is a recorded podcast, not a live one, because of all the traveling we’re doing lately, so we are pre-recording some of these sessions. Today, we’re going to talk about WordPress security, but not the typical WordPress security, not the technical aspect of it, but more how outsiders, enterprises, and other businesses perceive WordPress security. To discuss this with me today, my guest is Dan Knauss. Hello Dan, how are you?

Dan Knauss: Great. Good to be on your show, Robert. Thanks.

Robert Abela: Before we start, can you please introduce yourself and tell our guests a bit about your history and your experience?

Dan Knauss: Sure. I’m Dan Knauss. Most recently, I was a solution architect for a couple of years at Multidots, one of the VIP partners in the enterprise WordPress space. I may be joining a local agency and looking at some new things at this time. Before that, I worked on Solid Security under Liquid Web at StellarWP, and through my own consultancy and other work, I’ve been in the WordPress space and open source for a long, long time, going back a little before WordPress. I’ve worked with a lot of different open-source systems, and security has always been either at the front or a close side interest of mine.

Robert Abela: You’ve also written in the past about security, right?

Dan Knauss: Yes, correct.

Robert Abela: Good. Let’s start there, because as you said, you’ve also been a senior solution architect. First of all, what exactly does the job include?

Dan Knauss: That covers a wide range in actuality. It depends on the particular agency model you have, but it didn’t feel much different from when I was a solo consultant engaging in the sales process. Really, I think the ability to communicate well to any kind of audience, from a high level down to technical details and back up again, and to get between designers and developers on your internal team, and then whoever the client is, is key.

There’s always that initial consulting role where it’s kind of the closer a lot of the time, or what clinches deals to build confidence that, hey, here’s how we could do this. Here are some early demos or proofs of concept, or going through a discovery process and often leading that on bigger projects, working closely with the client team to figure out the requirements and put together a project, and then carrying it through some bit of project management and delivery.

Really, the relationship that comes out of that is what matters. You want to end up in a long-term partnership. Trust is always what’s built and needs to be sustained, and trust is a huge part of open source and really security. Those are very similar concepts and words that are always close, whether security is part of the direct conversation or not. Trust and the values around that and open source are really key to any client-facing role in a WordPress or tech organization, certainly agencies.

Robert Abela: Interesting. In fact, that’s exactly what we’re going to talk about today: security, trust, and some other stuff. When you walk into a meeting, into a conversation with an enterprise or a business, and you mention WordPress, because of course we know WordPress’s reputation over the last few years, different reports, and now especially with AI, what’s the default reaction from stakeholders when you mention WordPress?

Dan Knauss: They’re usually already coming because they know about it and want it, certainly by the time I would be dealing with clients. Long before that, I felt that it had long sold itself. We might be moving into more disruptive, competitive times, with different changes happening in the market, but it’s been a terrific brand.

In an enterprise context, I saw that again and again. That’s what brings them in. Sometimes, in a long relationship with a bigger client, when you’re moving into dealing with other divisions in a company, there might be different concerns. You’re often coming in dealing with marketing teams or teams that work inside a CMS a lot. WordPress is really suited for that, with great hosting partners around publishing and content. Those teams love and want WordPress.

When you get into deeper technical integrations and things like that, it’s a different group of people. You’re talking with different priorities and concerns. It would be less likely, in my experience, for security to be a major issue in the way people imagine. I think this is across the board. It doesn’t matter if you’re providing WordPress or some other platform. It’s not where the client is always thinking. That’s just a kind of industry and cultural reality.

There aren’t many enterprises, unless they’re already in a high-security industry or have had issues in the past, where security is first and foremost on their minds. But it should be. Everyone should by now really be prioritizing having a security culture.

Robert Abela: It’s good to hear that when you walk into these meetings, people really want WordPress. But as you said, when you start talking to the technical team, perceptions might change a bit. What assumptions do technical teams usually have about WordPress, specifically about security?

Dan Knauss: I haven’t run into an experience where that was really a major issue. It might be more about their prejudices around capabilities. If it’s security, it would be more of a concern. This is fine, this is sort of containerized outside of our infrastructure when we’re using something like WordPress VIP or Pantheon, or we’re bringing in a major hosting partner that’s only going to be integrated with deeper internal systems to the extent that’s part of what we’re building.

That’s where it becomes a question. Often, you’re integrating with a Microsoft identity provider, an SSO experience, which actually gives them control over who’s got access to WordPress and oversight for that. Or they may want to integrate with the SIEM and basically plug something like an activity log into it so they can keep an eye on what’s going on inside the application.

I haven’t had a lot of people come at this from the enterprise level, the way they do in smaller agencies or the middle mass market, where you hear all about plugin security all the time. That’s really not the case, in my experience. At the enterprise level, it’s a different world.

Robert Abela: Good to hear. Do you think all these public reports, headlines, and insecure narrative-type stories have some sort of impact on these conversations and on the way people look at WordPress?

Dan Knauss: I think so. They obviously must, but it does seem to stay in certain market segments. When you get stories that are generally quite unfair or misdirected at WordPress, that shapes perception. There was something about a year ago, maybe in the UK government or some para-governmental site, where people made a fuss because someone had discovered that you could do a kind of directory traversal and find documents in the media library unless steps had been taken to lock that down.

Someone had some pre-press news that wasn’t meant to go out yet, and people said, “This is WordPress, it’s not secure.” That’s really outside the scope of what WordPress is supposed to protect. That wasn’t really an issue. Often that’s the case. Many vulnerabilities are misclassified or hyped a bit, and the conditions needed to exploit them are very minimal.

When I was working with a security plugin ecosystem that was oriented more toward the huge third-party plugin problem. But in an enterprise build, we’re not putting in any old plugin, or that many of them. You have a contained system where everything that’s going into it has been vetted and scoped and is either something we built or are maintaining.

That’s definitely a point where I’ve always thought some of the more robust and established plugin products could do more to work well with the enterprise space and extend their business that way. But there really are quite different worlds, and I think that’s a good thing.

Robert Abela: You mentioned earlier that there’s a difference in perception because, in the mid-small business market, there’s this whole idea that WordPress is insecure. But you said enterprise is a bit different. What is different exactly in an enterprise from the mid-small business size?

Dan Knauss: At that level, the market has been won by solid hosting solutions, a solid brand, and terrific agencies that do great work. The facts are better understood. WordPress is very battle-tested and hardened at scale. It has benefited from its age and openness.

It’s really that whole third-party plugin environment and lower-market hosting that bring risk, along with the giant footprint. If you look at enterprise WordPress, it’s a pretty small but lucrative subpopulation out of maybe close to a billion WordPress sites. A lot of those installs have probably gotten an obsolete plugin or dependency somewhere in there, at least one, so there is some exploitability there. Since you can do that at scale even better now with AI tools, it’s always been a huge target.

Robert Abela: Do you think these types of reports or newsletters create more noise than clarity? I’m subscribed to some newsletters, and almost daily, some vendors send messages like 200,000 websites vulnerable to this, or 200,000 to that. Do you think these actually create more noise than clarity about what is happening for real?

Dan Knauss: That’s possible. I think we probably do have to revise a bit the old Eric Raymond riff on Linus Torvalds, that more transparency is good, openness is good, more eyes on bugs and potential issues are better. But when it’s a zillion different newsletters and websites, and people are reporting things in a yellow-journalistic, hyped-up way, that’s not helpful.

When I was producing disclosures and taking part in emails and things going out like that, you always want to think carefully about how you go about it, especially when it’s your product. People suddenly become a lot more responsible then. I recently went back to an old project I started to write a WordPress security style guide about how we should think about it and how we should write about it.

I think there’s a good way to do it, and shotgunning the whole world with vulnerability messages is not helpful. That’s true across the board. Vulnerabilities have been on an exponential curve. It’s never gone down from one year to the next on any platform. If you follow industry security newsletters, it’s mostly Adobe, or CrowdStrike takes down the airlines for a day. WordPress and its plugins are big in its world, but there’s so much else going on, too.

Contributing to the noise is not ideal. Everyone who wants solutions is looking for more actionable and focused information that they can use and maintain in their own area of concern. Is this affecting me? What do I need to do? The better hosts will generally take care of that for you, and it sort of goes with the territory of being an agency to keep in front of those things.

Robert Abela: It almost feels like scaremongering in some cases.

Dan Knauss: Some definitely take it that way, yes. An uninformed perception might be to see the whole brand as insecure somehow, but that’s not so.

Robert Abela: As an agency, professional, or consultant, if they are approached by a customer of any size and they have this concern because they’ve just seen a report or newsletter, what are the best ways to handle such cases?

Dan Knauss: If people are open to being educated, that’s a good thing to do. Try to break it down in simpler terms. When people don’t understand the system, things are scarier. You want to move away from fear, uncertainty, and doubt, and scope things down. What is really affecting us, and what action can we take?

A lot of the time, you can simply point out that this isn’t really a relevant concern to you, or it’s easily addressed, or it has already been handled proactively by an agency, provider, vendor, or host. Maybe sometimes it’s explaining the way open source works and how, at least the better pros in the market, do disclosures and get on top of security releases quite quickly.

We recently had a big batch of security releases go out together. I didn’t see anyone write about it, but I believe a lot of AI-assisted research has gone into finding more bugs. When you find out about it, it’s often because it’s already been fixed. That’s a good thing. It’s coming to light.

Sometimes explaining that helps. There are very few zero-day situations that are going to affect a lot of people. Those are the rare and exceptional cases. The rest is: if you’ve been doing diligent updates and being selective with where you host and how you manage your site and what you install on it, you’re probably fine.

I’ve personally had my hands on many, many hundreds of sites in the last 15 years. Nothing I have been personally responsible for has had an issue since around the time of TimThumb, which is where Wordfence kind of got started and where the WordPress security space opened up more because everybody was using that graphics library, and it caused a lot of plugins and themes to be vulnerable.

Robert Abela: Do you think the fact that WordPress is so accessible, and therefore attracts a lot of people who might not know what it takes to maintain a website, could also be part of the problem? So people assume it’s less secure because they see people making mistakes?

Dan Knauss: I don’t know if that’s the first thing in the consumer market. I think the bigger competitive risk now is other things. In the mass common-user market, small businesses want to solve a business problem and build something quickly. It’s always been a problem that they don’t think about security, and that’s probably true at a much higher level, too.

Outside technical audiences, there hasn’t been a lot of work done to break down and explain the real risks, responsibilities, and how to make it feel manageable. More and more, a ton of it has just become user management: who has you given access to, why, how long do they need it, and do they have the appropriate privilege restriction?

That, more and more in WordPress and everywhere else, has become a key issue, especially with phishing getting really capable. It’s our OWASP Top 10 number one issue: broken access controls. It’s not WordPress-specific. If you get in through some broken plugin or some other platform or source that gives you the ability to create a user account, escalate its privileges, or act with privileges you shouldn’t have, that sort of thing has really increased.

So it comes down to paying attention. Who’s on your site? What kind of activity is being logged there? Are you even looking?

The British Museum, for example, had a big public postmortem after a ransomware incident. It boiled down to having so many different systems and vendors, with no real governance. They weren’t even able to fully pin it down, but it was highly likely somebody got in through a rogue account or a user account created for an external API or vendor. Some access point had been opened and left open, and was compromised. From there, somebody dug deeper into the system and installed ransomware.

You have the same pattern even with small WordPress sites. They may not be the same kind of high-value target, but they can be exploited and used to support other attacks. If that’s coming in through user accounts or a plugin that has broken security permissioning, that’s on the people responsible for the site, and it should be visible to them.

We could do a lot more to educate people about that. It doesn’t really matter what platform you’re on. WordPress actually does give you the opportunity to see what’s going on and control that, to understand the surface. I’ve never seen anyone really explain in plain terms to common users: what’s an attack surface, what’s the threat model, what’s a manageable and simple approach to verify that this is a hard target, and I know where to watch for mischief?

Robert Abela: You are 100% right. I was at CloudFest a few weeks ago and attended quite a few security talks and presentations. There were reports from Patchstack, and the two most common attacks were exploitation of vulnerabilities in plugins, especially outdated plugins, which is a human mistake because people should update them, and user account issues, basically as you were saying.

There was this security guy who joked that because of AI, phishing has become much better than the legitimate emails, so it’s really hard for people to recognize them. It all boils down to visibility on what’s happening on your website, what users are doing, and what access they have. Quite frankly, all we’re seeing is user mistakes.

Dan Knauss: Yes. There are a lot of ways to classify breaches, and if you look at the best industry-wide breach analysis reports, Verizon and IBM both put out annual reports, and it’s amazing how much the primary answer is simply that someone made a mistake. Someone screwed up is often the correct general explanation for what went wrong.

Past basic password security, the messaging really hasn’t shifted enough, especially in WordPress, to say this is now a user-management and user-access issue. The principle of least privilege and visibility on what your users are doing and how open your application is to other things accessing it matters a lot.

Robert Abela: I agree 100%. Even some really big attacks come down to that. I remember years ago reading about the Apache.org issue. When you traced it back, it was a phishing attack. The attackers saw that the Apache foundation was using an outdated bug-tracking system, they posted something like, “Hi, I need help with this bug,” with a link, support people clicked it, and the rest is history. They escalated privileges all the way to root access. So many people think about these complex things, but a lot of even the big attacks are user mistakes.

Do you think WordPress is judged more harshly than other platforms when it comes to security because of these things? People think it’s insecure, but the reality, as we’re seeing, is that it’s more user issues than WordPress per se.

Dan Knauss: Yes, and that cuts across all platforms. That seems to be what’s being targeted more and more. If someone gets into your own personal system through your phone, through something you linked, or through an insecure network, and accesses your Slack through session theft or keylogging, that’s really giving them the keys to the kingdom. Then WordPress and other applications come out of that.

Educating people more about that is helpful. There are definitely things that can be done. At the same time, part of the reality of having a durable 20-plus-year platform is that it does not have the latest architecture or approaches to everything. It’s well hardened and backward compatible, and there’s a lot of backporting to ensure security further back in time.

But there are compelling arguments from people like Yoast and others that we’re overdue for some refactoring and fundamental maintenance in areas where security is viable but where you could definitely reduce the footprint and reduce the target surface more. The big one for me is not having a system where plugins can have free rein over the file system and run with the same privileges as the application. If we could scope that in a little more and fence that in, that would certainly be helpful.

That would primarily be protecting the core against what’s coming in from plugins. I also like pushing more awareness and responsibility to plugin developers. We have a pretty streamlined plugin repo process for all its age and volunteer-driven nature, but the standards could probably be elevated over time.

Especially if we’re seeing more code coming in from people using AI-assisted development, the bar should be higher. If you can’t verify under a higher testing threshold, that’s a problem. We can raise the bar on ensuring that what comes into the plugin repo has passed an ever-increasing set of testing requirements, and security is a big part of that.

Robert Abela: For people who are maybe not familiar, we were exchanging some emails before Cloudflare released EmDahs, and one of their biggest security angles is that they’re going to sandbox plugins, as opposed to WordPress, where you install a plugin, and it basically has access to everything. Matt also posted that the fact that plugins can do everything on a WordPress installation literally is one of the main features, but also that maybe it’s time to improve some things.

I know you have a plugin with Sudo, which is quite a good idea. What are your thoughts on how these things can be implemented or improved?

Dan Knauss: Historically, I kind of see it Matt’s way in that we probably wouldn’t be here if WordPress hadn’t been as open as it was. That architecture dates back to WordPress as a blog with a very simple architecture. Growth wouldn’t have happened if it weren’t open. There was a low threshold for people to learn how to build something and put a single-file plugin in there.

The question now is whether there’s an inflection point where this has become absolutely necessary and easier to do. If you’re building a whole new application now, you’re going to build it on the standards and best practices of the day, and six months from now it’ll start to be obsolete, and in another couple of years the same things will fall to you.

Seeing this in a blamey way is not helpful. The web has been around long enough that we need to think in terms of maintenance, care, and responsibility to projects that are serious, have a community around them, and have an ecosystem around them that wants to go on for a long time. Just because you can build something the way it should be built now in one model, that’s far too short-term in thinking.

How do we build for the long-term future, given the reality of where we are now and what we’ve got? There are things in the fundamental architecture of WordPress that people have been working around and working with successfully and securely for a long time. But the tradeoffs have performance hits sometimes, and definitely, the security issue would be mitigated significantly if plugins didn’t have full rein over the system.

Those are good questions to raise. They’re really important. Where can we put our priorities? Maybe the community can find some ways to rally around the value of maintenance and the people focused on those things. They’re not the hottest or most exciting issues you can market, but they’re really important.

Robert Abela: You worked with enterprises, but you were also, for a few years, the editor of PostStatus, so you see WordPress from a lot of different angles. How do you think something like EmDahs and all the hype around it affects the way people look at WordPress? I’ve been to WordCamp, CloudFest, and a few other conferences this year, and I get mixed messages. Some say it’s the end of WordPress. Others say this could be good because free websites and free plugins might move elsewhere, and WordPress may become even more of a business and enterprise solution. How do you think these changes affect perception?

Dan Knauss: I don’t really have more than gut intuition there. I haven’t followed it that closely, and I haven’t gotten a lot of outside-WordPress takes on it. Some developer friends who worked in and around WordPress didn’t even notice it right away. They come back around to it, and then the conversation becomes, well, here’s why WordPress is the way it is, and here are the arguments from people like Yoast or Hendrick about what could change.

It’s a community project, and those things are open to being addressed and dealt with. People have definitely tried. Maybe the time has come to find some ways forward, find some low-hanging fruit, and make some progress on those items.

I think the EmDah thing is a very inside-baseball type of discussion. I don’t think it’s likely to register too far out. Launching on April 1, with no real community behind it, I’d be kind of surprised if it coheres into something people want to carry forward, especially with the platform-vendor lock-in that comes with it.

But what it has generated is really awesome thinking together, and really good questions and writing. I think that’s going to have an impact. To me, the question is whether, a year or two from now, this changed how WordPress as a whole, the ecosystem, community, major hosts, and major figures within it learned from this and whether it changed the course of history for WordPress. I think it should. I think it has to. It just told us things we already knew, but in one concentrated way.

Robert Abela: Do you think people in general are overreacting to these kinds of new releases and news? I’ve seen the “next WordPress killer” message before with Shopify, Wix, and others. Is this maybe more overreaction than substance?

Dan Knauss: I think it’s usually a superficial reaction. I tend to ignore that kind of stuff because you just can’t predict things from single events like that. WordPress is so big and established that the thing serious people worry about is the slow death of a thousand cuts, or your own foot-guns, or your own lack of maintenance.

There’s a lot to be said for keeping things simple and not reacting. Trying to be the latest and best is not what wins the long race. These deeper fundamental questions about how you modernize architecture and what you can refactor go far below the hype.

If you fixed all of these things, you could market that and the people who matter would love it, but it’s never going to translate into the kind of loud splashy story of “here’s the newest thing” or “here’s the thing that’s going to destroy us.” That’s just not the serious level.

If you’re talking about WordPress and systems like that, the big-picture, long-term approach is the one worth listening to. There are a lot of smaller people in the space, a lot of small businesses and smaller agencies, who have been doing this for 10 or 20 years. They want a solid platform, reliability, and good hosting partners. These are not temporary structures. We’re building something more like a cathedral. Some people think about their businesses that way, and that’s what we want to nurture and encourage.

Robert Abela: That’s a very good point. In fact, I think Syed Balkhi posted about this. When you open LinkedIn, you think everyone is building the next best thing and everyone is using AI like crazy. But from some research they’ve done, most people use AI just as a glorified Google, nothing more. Because we follow a small percentage of people who are leading the industry, we think the whole industry is going that way, so people tend to panic. Could that be the case here, too?

Dan Knauss: I think so. There are definitely tech and WordPress bubbles. I like to stay grounded by talking with younger people who are very new to working on the web and with current technologies, and then hit them with the voice of experience: yes, that looks nice and flashy, but as a business-oriented solution, here are all the reasons why something more proven and established is easier to maintain and has a lower cost in the long run.

Then there are other people I’d put in the small-business world, brick-and-mortar stores, people at the local farm market, musicians. They know and use WordPress. They know, to some extent, that it’s an open platform. There are often people who don’t like social media, don’t like being trapped in noisy platforms that limit their reach, and then raise the price tag. It surprised me how many people I know in the music industry in Canada care about that and see WordPress as set apart. It’s also true in independent journalism.

There’s a new generation that needs that message translated to them. Not just the creator economy. People of all ages are doing things where they really want control over their platform and their own distribution and reach. Security and all the technical stuff are off to the side for them. They want it to be easy. But longevity matters to them. They don’t want to build something flashy and new that next year they can’t afford, or that has changed in ways they dislike.

Robert Abela: That’s also a good point. If you go to WordCamp, a lot of attendees are involved in the WordPress community somehow, so of course, they’re following the news. But if you speak to a systems engineer from a small bank or a small local insurance company, they know WordPress because they use it, but they’re not following the whole WordPress industry story, where it’s heading, who’s doing what. Usually, they don’t have the same impression. They don’t even know what EmDahs is. That could be part of the overreaction, too.

Dan Knauss: I think so. If you just listen broadly, it’s an incredible brand. There’s nothing else quite like it. I’ve been most impressed by that in startup-tech-incubator contexts. With our local WordPress meetup in Edmonton, when we do a big networking event alongside Python, Ruby, JavaScript, Linux, hardware, marketing, and UX groups, everyone knows about WordPress. No one is like, “What’s WordPress?”

Dan Knauss: It’s a very all-ages, multicultural audience, and the majority have some real use case close to them. They’re using it now, they used it somewhere else, they have questions, or they freelance with it. There are so many different things going on with it. It both benefits and suffers a little from being this multi-tool of broad appeal and usability.

It would be hard to market, and the fact that we really haven’t marketed it in a singular way is part of the result. It just became a ubiquitous tool. All these people have used it and are using it. The question is: how do we keep that going?

I don’t think security is on the tip of anyone’s tongue unless they’ve been hacked. Then the term becomes “my site got hacked” or “this plugin wasn’t updated.” I’ve done presentations on that kind of thing. But it doesn’t land outside the WordPress-insider world the same way it does for people who get those newsletters every week. People are not thinking of it in terms of security at all. They probably should have a little more, but really, we should just keep giving them a better and better product.

Ideally, things like scoping the reach of plugins and their permissions are important. There are a lot of messages I wish we got out that were more positive and more educational.

Robert Abela: Is there something that agencies or people in the WordPress community can do to slowly improve WordPress’s reputation, especially when it comes to security?

Dan Knauss: I think it already has a solid reputation, and barring some catastrophic event or really bad press event, even that seems not to land too far. CrowdStrike and Microsoft can get away with all kinds of things. We haven’t had a TimThumb-scale event hit some major corporate clients in a long time, and that’s the kind of scenario I’d worry about.

Industry-wide, though, there’s been a shift over the last five-ish years where bigger tech-security conferences and analyst groups like Forrester and Gartner have shifted their messaging. The onus is really on users and user management. They’re thinking less in the old plugin-security-market way of “how do I keep it all out?” and more in layers, but also in planning for when things get through.

If you’re on the web long enough, or you have complex systems, or a high-value target, plan for the worst. That’s part of protection, too. Agencies of any size can work that into their business. Their clients care about protecting their information, assets, brand, and customers. That increasingly comes down to limiting the blast radius and diminishing the potential harm. If the worst happens, keep it within a small circle and understand what to do next.

That is sinking in more at a high level. Build a security-minded culture where everyone is aware of the major threats to themselves and their role, which for regular people is a lot of email and text-based phishing. That’s something we can push more if we choose to educate people about it.

It’s also a value add if you’re selling services. No one really wants to pay for security when they’re thinking about a project, because it feels like an add-on. But given today’s realities, people need to price that into what they’re offering and work with a security solution or partner. There’s definitely a lot of potential there, especially with better user management. Teach clients and end users that someone has to be managing not just content but user policies and who can do what.

Robert Abela: Unfortunately, security is always a bit like an afterthought. It’s like insurance. Some people risk it, and then if something bad happens, they regret it. I can see that at Melapress because of the nature of our plugins, but even before WordPress, when I was working for security startups, it was always the same. People contacted us after they had been hacked, not before.

It’s the same with our plugins. With activity logs, it’s always, “We’ve been hacked, we’re an agency, this happened to our client website, and we want to know what happened.” So it’s always an afterthought, which is a pity. Hopefully, educating people is very important.

When we started years ago, the message was more like, “You need this or you’re going to get hacked.” Over the last few years, we’ve been trying to be more positive in our messaging: you need this to keep accountability, to know what’s happening, to stay in control, rather than using scare tactics. Scaremongering might sell, but it’s clearly not helping the reputation in general, and it might push people away.

Hopefully, by educating users and using better messaging, it will help a lot. Thanks a lot, Dan. Before we end this episode, is there anything you’d like to mention or that we forgot to mention?

Dan Knauss: I didn’t really plan to promote my own work, but I have been working on a number of interesting projects to learn more about what’s possible with AI tools and to scratch some old itches I’ve had with WordPress. If anyone wants to check out my GitHub account, it’s dknauss.

One thing that has generated the most interest is pulling together things I’ve learned and overheard and talked about with really great security and developer minds over the years, and that’s WP Sudo, as in the Linux “superuser do.” That’s an early experiment I’d love people’s feedback on, as a way to gate more dangerous actions in WordPress. If you’re going to do something sensitive, you need to reauthenticate.

This covers not just the admin interface but all the other ways privileged access could run a delete command or change a setting. It’s kind of a learning thing for me, but a lot of interesting thoughts come out of it. It’s one way to mitigate the harm of potentially compromised plugins, broken access controls, and things like that, and to get insight into who is doing what because you can log all of those requests.

It works with two-factor and with activity log plugins, since those were logical to test and connect with. I’ve also got some documentation projects in there that are more enterprise or security-documentation oriented, including a style guide for my philosophy and approach, down to how you write about code, glossary work, and things like that for anyone who wants to write about security in the WordPress space.

It really does start with how we focus on the positives, empower people, reduce uncertainty and fear, and do responsible disclosure if you’re talking about your own product and things like that.

Robert Abela: Good. Thanks a lot. We’ll add a link to your GitHub and other projects we do, like the Sudo plugin, in the show notes. Do you have a website where people can find a central place with your links and information, and maybe get in touch with you?

Dan Knauss: Yes. I have a Linktree-type thing on my Gravatar site, and a couple of domains point there. That’s dan.knauss.ca, and that connects to all my stuff.

Robert Abela: Good. We’re going to link that as well in the show notes. Thank you very much, Dan. Thank you, everyone, for listening.

Dan Knauss: Thank you. Thanks. It was nice speaking to you.

Robert Abela: Definitely very informative, and hopefully, within a few years, people will have a much better impression of WordPress.

Dan Knauss: I think so. Thank you.

FIELD:
Lana Miro Avatar