Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

WordPress

66 articles tagged WordPress, newest first.

Block AI training if you want. Never block AI answers.

Block AI training if you want. Never block AI answers.

Blocking GPTBot costs you nothing. Blocking OAI-SearchBot deletes you from ChatGPT. What 50,000 live robots.txt files show about telling them apart.

One Search Finds That User on Every Site You Manage

One Search Finds That User on Every Site You Manage

Search one person across every connected Joomla and WordPress site, then add, edit, block or delete accounts and change group membership without logging in.

Release Radar, a Free Joomla and WordPress Release Tracker

Release Radar, a Free Joomla and WordPress Release Tracker

A free public log of new Joomla and WordPress extension releases, including the paid ones no plugin directory covers. RSS and JSON, no account needed.

A Web File Manager for Your Joomla and WordPress Sites

A Web File Manager for Your Joomla and WordPress Sites

mySites.guru now includes a secure, opt-in web file manager for Joomla and WordPress: browse, edit, upload and delete files with no SFTP client needed.

Impostor Files: How to find every file in a core folder that core never shipped

Impostor Files: How to find every file in a core folder that core never shipped

Joomla 5.4.7 ships exactly one file directly in /administrator/. Impostor Files lists everything else sitting in folders the CMS itself owns.

What Site Audits Reveal About Joomla and WordPress Security

What Site Audits Reveal About Joomla and WordPress Security

99% of Joomla sites don't force MFA and 91.8% of WordPress sites skip DISALLOW_FILE_MODS. Real audit data on which security features get used.

Slower on purpose: the new Update Queue, and why it is off by default

Slower on purpose: the new Update Queue, and why it is off by default

Firing every update at once is what takes a shared server down. mySites.guru's new Update Queue runs one update at a time per server, off by default.

Summer 2026: Everything New in mySites.guru

Summer 2026: Everything New in mySites.guru

Everything new in mySites.guru this summer: 38 new tools, 40 improvements, and the 19 Joomla extension vulnerabilities we found and disclosed ourselves.

The latest 90 reviews of mySites.guru - and what they said

The latest 90 reviews of mySites.guru - and what they said

Ninety people left mySites.guru a five-star review this summer. We counted what they mentioned, and the most common word was not security, updates or price.

One VEL for Every Joomla and WordPress Site

One VEL for Every Joomla and WordPress Site

The Joomla VEL (Vulnerable Extension List) only covers Joomla and never checks your sites. mySites.guru tracks both CMSes and flags yours directly.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.

Reinfected? Check Every Crontab, Not Just Yours

Reinfected? Check Every Crontab, Not Just Yours

Your cPanel cron jobs look clean but the site reinfects anyway. The cron rebuilding the malware is hiding in a crontab your account can't see. Here is where.

Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End

Hacked Yesterday, Exploited Today: Why One Cleanup Is Never the End

The first hack plants a dormant dropper. The real damage comes in the second wave, days or weeks later. Here is why monitoring beats one-shot cleanup.

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)

Avada Builder 3.15.4 fixes a critical unauthenticated file deletion flaw (CVE-2026-8713, CVSS 9.1) that can delete wp-config.php and take over the site.

WP_AI_SUPPORT: Disable WordPress 7 AI Across Every Site

WP_AI_SUPPORT: Disable WordPress 7 AI Across Every Site

WordPress 7.0 ships with built-in AI features enabled by default. Disable WP_AI_SUPPORT across every WordPress site you manage in one click with mySites.guru.

mySites.guru is fully compatible with WordPress 7.0

mySites.guru is fully compatible with WordPress 7.0

WordPress 7.0 "Armstrong" shipped on 20 May 2026. mySites.guru works perfectly with it. Backup, update, and control auto-updates across every site.

Avada Builder Patches Two Security Issues in 3.15.3

Avada Builder Patches Two Security Issues in 3.15.3

Avada Builder 3.15.3 patches an unauthenticated SQL injection and a Subscriber-level file read across 1 million WordPress sites. Find affected sites.

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug

Wordfence blocked 3,936 attacks in 24 hours against Breeze Cache below 2.4.5. CVE-2026-3844 is unauthenticated RCE on 400,000+ WordPress sites.

AcyMailing Vulnerability Also Affects Joomla Sites

AcyMailing Vulnerability Also Affects Joomla Sites

CVE-2026-3614 is listed as a WordPress bug. We diffed the 10.8.1 and 10.8.2 source and the same vulnerable code ships to Joomla sites too.

The WordPress Plugin You Trusted Was Sold to an Attacker

The WordPress Plugin You Trusted Was Sold to an Attacker

A buyer acquired 31 WordPress plugins, planted a backdoor in August 2025, and activated it in April 2026. Here is what happened and how to check your sites.

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise

Smart Slider 3 Pro 3.5.1.35 was a malicious release pushed through the official update channel. RCE backdoor, hidden admin users. Update to 3.5.1.36.

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again

CVE-2026-0740 is a CVSS 9.8 unauthenticated RCE in the Ninja Forms File Uploads AJAX handler, exploited with over 118,600 attempts blocked by Wordfence.

4 Major WordPress Plugins Patched Security Flaws in March 2026

4 Major WordPress Plugins Patched Security Flaws in March 2026

Elementor, Yoast SEO, WPForms, and Really Simple Security all shipped security patches in March 2026. What was fixed, and how to verify your sites.

AJAX Endpoints Are A Big CMS Security Blind Spot

AJAX Endpoints Are A Big CMS Security Blind Spot

Five AJAX and API vulnerabilities hit Joomla and WordPress in March 2026, all sharing one root cause. Here is what went wrong and how to protect your sites.

WordPress 7 Technical Requirements Check: Is Your Hosting Ready?

WordPress 7 Technical Requirements Check: Is Your Hosting Ready?

WordPress 7 requires PHP 7.4+ and MySQL 8.0+. Run a free hosting check across your entire portfolio to find which sites meet the technical requirements.

Smart Slider 3 Hack Allows Any File to Be Downloaded

Smart Slider 3 Hack Allows Any File to Be Downloaded

CVE-2026-3098 lets any subscriber download wp-config.php from 800,000 WordPress sites running Smart Slider 3. How to check and fix it.

How to Check Your Sites for WordPress 7.0 Compatibility

How to Check Your Sites for WordPress 7.0 Compatibility

WordPress 7.0 requires PHP 7.4+ and MySQL 8.0+, dropping PHP 7.2/7.3. Sites on older versions won't auto-update. Check your whole portfolio in seconds.

How to Clean Up Dangerous Files Left on Your Joomla Web Server

How to Clean Up Dangerous Files Left on Your Joomla Web Server

ZIP archives, SQL dumps, and PHP error logs left on your Joomla server are security risks waiting to be exploited. Find and remove them before an attacker does.

How to Remove the Sample Page and Hello World Post in WordPress with One Click

How to Remove the Sample Page and Hello World Post in WordPress with One Click

Every WordPress install ships with a Sample Page and Hello World post. Learn why they hurt SEO and how mySites.guru removes them across all your sites.

Snapshot vs Audit: What's the Difference?

Snapshot vs Audit: What's the Difference?

mySites.guru checks your sites two ways: quick snapshots of config and settings, and deep audits that scan every file. Here's when to use each.

How to Verify Your Joomla Site's Email Configuration Actually Works

How to Verify Your Joomla Site's Email Configuration Actually Works

Joomla and WordPress contact forms can silently fail. Check SMTP settings, test mail delivery, and catch email misconfigurations across all your sites.

Is My WordPress Site Hacked? How to Check and What to Do Next

Is My WordPress Site Hacked? How to Check and What to Do Next

Think your WordPress site has been hacked? Here are the signs to look for, how to confirm it, and what to do in the first 24 hours to contain the damage.

How to Enforce Minor Upgrades Only in WordPress

How to Enforce Minor Upgrades Only in WordPress

Stop WordPress from jumping major versions automatically while still getting security patches. How WP_AUTO_UPDATE_CORE works.

WordPress 6.9.2, 6.9.3, and 6.9.4: 10 Security Fixes, a Crash, and Incomplete Patches

WordPress 6.9.2, 6.9.3, and 6.9.4: 10 Security Fixes, a Crash, and Incomplete Patches

WordPress 6.9.2 crashed sites with a white screen, 6.9.3 fixed it, then 6.9.4 completed three missing security patches. What happened and how to recover.

How to Disable the WordPress Admin Menu Bar on the Frontend When Logged In

How to Disable the WordPress Admin Menu Bar on the Frontend When Logged In

Remove the WordPress admin toolbar from your frontend with a per-user toggle, functions.php filter, or one click across all your sites. Code included.

How to Stop Automatic Updates in WordPress with One Click

How to Stop Automatic Updates in WordPress with One Click

WordPress auto-updates can break plugins, themes, and layouts without warning. Control updates across all your sites from one dashboard with mySites.guru.

How to Remove the WordPress Logo from the Admin Bar with One Click

How to Remove the WordPress Logo from the Admin Bar with One Click

The WordPress admin bar logo links to WordPress.org and identifies your CMS. Remove it in one click with mySites.guru for a white-label admin.

How to Stop Any Plugin Installs in WordPress Admin

How to Stop Any Plugin Installs in WordPress Admin

Add DISALLOW_FILE_MODS to wp-config.php to block plugin and theme installs in WordPress admin. Code snippet, wp-cli usage, and how to enforce it.

Hidden Files Lurking on Your Web Server

Hidden Files Lurking on Your Web Server

Your web server probably has hidden dot-files you've never seen. Some are harmless, some were left by hackers. Here's how to find them.

WordPress Plugin Vulnerability Alerting

WordPress Plugin Vulnerability Alerting

mySites.guru cross-references every WordPress plugin on your sites against Wordfence, CVE and custom threat databases, flagging vulnerable plugins instantly.

Add unlimited Joomla and WordPress sites to mySites.guru

Add unlimited Joomla and WordPress sites to mySites.guru

Step-by-step guide to connecting your first Joomla or WordPress site to mySites.guru - supports unlimited sites for one flat monthly fee.

Backup 1000s of Sites from One Dashboard

Backup 1000s of Sites from One Dashboard

Schedule and manage Akeeba Backup across thousands of Joomla and WordPress sites from a single mySites.guru dashboard.

Backup All Your Sites With One Click

Backup All Your Sites With One Click

The one-click Backup All Sites button is back in mySites.guru, now with a per-site default backup profile to power the bulk backup queue.

White-Label Client Reports for Your Sites

White-Label Client Reports for Your Sites

Build unlimited branded report templates in mySites.guru. Assign them to scheduled reports and send white-label updates directly to clients.

End-of-Life Version Support in mySites.guru

End-of-Life Version Support in mySites.guru

mySites.guru monitors end-of-life Joomla and WordPress versions from 1.5 to 6, alerting you when sites run unsupported software that puts them at risk.

Find Hacks and Backdoors in WordPress & Joomla

Find Hacks and Backdoors in WordPress & Joomla

Scan your WordPress and Joomla sites for malware, backdoors, and suspicious files. Hash-based detection and 1,500+ regex patterns.

Quick Snapshot of All Your Sites

Quick Snapshot of All Your Sites

The mySites.guru snapshot runs 140+ best-practice checks - PHP version, CMS config, security headers, SSL and more - twice a day on every connected site.

Get Expert Help for Your Sites Instantly

Get Expert Help for Your Sites Instantly

mySites.guru subscribers get direct access to Phil Taylor for fast expert help with any Joomla or WordPress problem - set fees, no ticket queues.

Clean a Hacked Site with Suspect Content and Hacked Files

Clean a Hacked Site with Suspect Content and Hacked Files

Use mySites.guru's Suspect Content and Hacked Files tools to find, confirm, and clean backdoors on a hacked Joomla or WordPress site, step by step.

Manage Multiple WordPress Sites Like a Pro

Manage Multiple WordPress Sites Like a Pro

Practical tips for managing multiple WordPress sites efficiently, covering centralised dashboards, backup strategies, security hardening and team workflows.

Upgrade 100s of Sites from One Dashboard

Upgrade 100s of Sites from One Dashboard

Run core and extension updates across hundreds of Joomla and WordPress sites from the mySites.guru dashboard.

Auto-Upgrade 1000s of Plugins & Extensions

Auto-Upgrade 1000s of Plugins & Extensions

Update Joomla extensions, WordPress plugins, and CMS cores across all your sites from one mySites.guru dashboard. Select all, click upgrade, done.

Install Extensions to 1000+ Sites at Once

Install Extensions to 1000+ Sites at Once

Install any Joomla extension or WordPress plugin across 1,000 sites in one go using the mySites.guru bulk install tool - no SSH or FTP needed.

Best Practice for Joomla & WordPress Sites

Best Practice for Joomla & WordPress Sites

Every mySites.guru snapshot and audit check comes with a detailed Learn More page explaining the best practice recommendation, the risk and how to fix it.

Manage Multiple Sites With Your Whole Team

Manage Multiple Sites With Your Whole Team

Add unlimited team members to your mySites.guru account with per-site and per-feature permissions. No per-seat fees.

Manage Multiple WordPress Sites

Manage Multiple WordPress Sites

Centralise updates, backups, security audits and one-click logins across all your WordPress sites. One dashboard, unlimited sites, £19.99/month.

90,000+ Sites Trust mySites.guru

90,000+ Sites Trust mySites.guru

Over 90,000 Joomla, WordPress, and PHP sites are connected to mySites.guru - all managed from a single dashboard invested into daily by its founder.

One-Click Admin Login to Any Site

One-Click Admin Login to Any Site

Skip the login page entirely. One click from mySites.guru logs you straight into any Joomla or WordPress admin console - no passwords stored, fully encrypted.

Deep Security Audit for WordPress & Joomla

Deep Security Audit for WordPress & Joomla

Surface-level scanners miss hidden malware. File-level audits check every line of code against 1,500+ patterns to find backdoors other tools miss.

Site Management Is More Than Just Updates

Site Management Is More Than Just Updates

Real site management means security audits, best practice checks, and hack detection - not just bulk updates, backups, and uptime pings.

Tools for Managing Multiple Sites

Tools for Managing Multiple Sites

The mySites.guru Snapshot All button refreshes version data, security checks and best practice results across every connected site in one click.

The Best Multi-Site Management Dashboard

The Best Multi-Site Management Dashboard

Manage unlimited WordPress, Joomla and PHP sites from one secure dashboard. Security audits, backups, uptime monitoring and more for GBP 19.99/month.

WordPress Debug Constants Explained

WordPress Debug Constants Explained

WP_DEBUG_LOG writes errors to a publicly accessible file that Google has indexed on thousands of sites. Here's the fix, plus what every debug constant does.

Universal User Management Across Sites

Universal User Management Across Sites

Search, edit, block and delete users across all your Joomla and WordPress sites from one page, and manage group membership without logging in to each site.

White-Label Activity Reports for Clients

White-Label Activity Reports for Clients

Send automated, branded site activity reports to your clients on any schedule. Covers updates, backups, audits, uptime and more - included in every plan.

WP Mayor's Five-Star Review of mySites.guru for WordPress

WP Mayor's Five-Star Review of mySites.guru for WordPress

WP Mayor gave mySites.guru a five-star rating after a month of hands-on testing. Here's what reviewer Kevin Wood found.

Browse every article