Security & OpsTwo-Factor for WordPress Admins Without Locking Yourself Out
WordPress administrator accounts cannot rely on a single defensive boundary when authentication spans both browser sessions and machine-to-machine interfaces.
WordPress ties background execution directly to incoming web traffic.

Security & OpsWordPress administrator accounts cannot rely on a single defensive boundary when authentication spans both browser sessions and machine-to-machine interfaces.
EngineeringMySQL 8.4 allows database administrators to enable, disable, and retarget the slow query log entirely at runtime.
I’ve been looking at information architecture, performance budgets, and accessibility patterns in casino directories, and this New Zealand guide is a handy real-world reference point.
IETF RFC 9111, published on June 6, 2022, established the baseline rules that govern modern web caching
A javascript: URL executes code directly inside the context of the active web page.
Every time WordPress handles a request, it runs a database query to pull every single row marked autoload = yes from the wp_options table directly into server memory.
Building a standalone WordPress plugin requires far fewer lines of code than most developers assume.
A backup archive sitting on a remote storage volume proves nothing until it boots inside an isolated environment.
Update: Yeah, looks like a few folks are missing. I’ll look into it!
Latest version: 1.0 - Released June 15th, 2025: This plugin allows you to display Pocket 'Read It Later' links next to each post on your blog.
If your plugin or theme uses custom post meta fields then you may want to store revisions to these fields when a post revision is saved.
It’s really easy to get an iPhone, iPad or other iOS device to access a local web server running on your development machine.
Basic Authentication (or BasicAuth) is not natively handled with the WordPress HTTP API.
On a default WordPress installation without external caching software, calling set_transient writes records directly into the wp_options database table.
WordPress requires custom post types to be registered on the init hook, where a single function call ties a 20-character database key to an array of runtime settings.
The WordPress codebase separates core updates from extension updates, yet many site administrators still treat background updates as a single switch.
A production WordPress site serving an entirely blank page cannot be diagnosed by flipping basic error switches in the open.
Dynamic properties are deprecated as of PHP 8.2.0, and WordPress.com said in 2024 that behavior deprecated in that release will be removed in PHP 9.
Omitting a permission_callback from register_rest_route has broken custom endpoint registrations since WordPress 5.5.0 treats missing authorization checks as an error.
EngineeringA clean Lighthouse run can mislead an engineering team for months. Synthetic audits run in a controlled environment with predefined device and network settings, generating a single score under static conditions.
A database index fails to accelerate a query when the structure of the index does not match how the execution engine reads data.
ToolingTyping localhost into a mobile browser fails instantly because the phone queries its own internal loopback interface rather than the workstation hosting the application.
ToolingA single malformed PHP file committed to a repository breaks continuous integration pipelines, blocks team branches, and burns developer time.
Every unexpected visual jump on a web page is recorded by the browser as a LayoutShift entry containing a specific property called sources.
ToolingLocal development runs directly on a workstation.
Setting DISALLOW_FILE_EDIT prevents administrators from modifying plugin and theme code directly inside the WordPress dashboard.
The Apache HTTP Server documentation defines its default Combined Log Format as %h %l %u %t "%r" %>s %b "%{Referer}i" "%{User-agent}i".
WordPress core ships with a dedicated credential system that isolates programmatic API access from interactive account logins.
Security & OpsEnforcing a content security policy on WordPress without diagnostic data routinely breaks the site.
From drinkcold.com: Desktop: Perhaps a handy program could be invented which automatically deleted your desktop contents every 14 days or something.
Dudes and dudettes, it’s competition time here at Ludicrous HQ. The story goes that I have 2 hard drives in my PC which used to be called XP and Data, because one had Windows XP installed on it and the other was just for data.
There are some good looking films coming out soon (and out already). Even though my bank balance doesn’t agree with me at the moment, I must get to the cinema to see all of these!
Here is some of what went on during my most recent trip to Newcastle-Upon-Bulman, and in usual Bon fashion I’m posting it three days after it actually happened.