Thank you for attending my talk

The Attacker That Never Logged In: Session Hijacking, Stolen Cookies, and the Blind Spot in WordPress Security

The slides are available for download.
Click the button below to download them.

During the talk I covered how WordPress authentication cookies and session tokens actually work, the different ways sessions get hijacked, and, the part most WordPress security setups miss entirely; post login security. In other words, what to do about visibility and control after someone is already logged in.

Below you’ll find the plugins that add the specific capabilities highlighted during the talk, the reports and data cited during the talk, and some further reading if you want to go deeper on any of it.

Plugins mentioned in this talk

The talk touches several distinct capabilities, which are; activity logging, session visibility, account lifecycle management, device recognition, and user roles. A plugin covering more than one is only listed once below, with all relevant capabilities noted alongside it.

PluginTypeCapabilities covered in this talk
WP Activity LogMelapress
Free & Premium options
Activity logging & forensic visibility (free)
Real-time view of logged-in users (premium)
Concurrent session limits (premium)
Inactive session expiry (premium)
StreamFree alternativeActivity logs only. No session visibility or session management
Melapress Login SecurityMelapress
Free & Premium options
Inactive user cleanup (free)
Temporary login links (free)
Restricted login times (premium)
Device recognition alerts (premium)
IP address /device limiting (premium)
Security questions (premium)
Temporary Login without PasswordFree alternativeTemporary login links only
Melapress Role EditorMelapress
Free
User roles & least privilege
PublishPress CapabilitiesFree alternativeUser roles & least privilege
Members – Membership & User Role Editor PluginFree alternativeUser roles & least privilege
WP 2FAMelapress
Free & Premium options
Add 2FA for sensitive user actions such as password reset.
Two FactorFree alternativeAdd 2FA (no option to add 2FA for sensitive user actions)

No free plugin covers real-time session visibility or concurrent session limits in full. That’s a genuine gap in the free plugin space.

Reports & research referenced in this talk

Security awareness training

Technical controls only go so far, and the talk closes on the human layer. A couple of starting points if you want to build this out for your team or clients:

  • SANS Security Awareness Training – widely regarded as the gold standard in security awareness training.
  • Pluralsight – more technical/educational than compliance-focused, better suited to developers and security champions than general staff. Troy Hunt has authored several relevant courses here, including password security, authentication, data breaches, modern identity, and web security fundamentals.

Further reading

Newsletter icon
Envelope icon