Blog

Practical guides on WordPress, hosting, security, and the web - from an Australian perspective.

Security·July 2026·6 min read

WordPress forced an update on everyone. Here's what that tells you.

WordPress 7.0.2 patched a pre-authentication remote code execution chain, and WordPress.org pushed it out as a forced update - something it very rarely does. What the flaw was, and why "I'll update it later" is the actual risk.

Read more
Strategy·February 2026·7 min read

AI will make every website look the same. WordPress is how you fight back.

Squarespace AI. Wix ADI. Framer AI. They all produce sites that look eerily similar. When your competitors' sites are AI-generated, your WordPress site becomes a competitive advantage.

Read more
Security·November 2025·5 min read

Why protecting wp-login.php is the first thing you should do

wp-login.php is the most attacked URL on the internet. Brute force bots hammer it 24/7 and most WordPress hosts do nothing about it. Here's why it matters and how to actually fix it.

Read more
Security·August 2025·6 min read

Why containerised hosting is fundamentally more secure than shared hosting

On shared hosting, one compromised site can affect every other account on the server. Containers change that equation entirely. Here's why the architecture matters.

Read more
Service·May 2025·5 min read

Why Australian-based support wins every time

Offshore support tickets, chatbots, and 48-hour response windows cost more than they save. Here's the real case for choosing a hosting provider you can actually talk to.

Read more
SEO·February 2025·6 min read

Does your server location affect your Google rankings?

Short answer: yes, more than most people realise. Server location affects page speed, and page speed is a Google ranking factor. Here's the full picture for Australian businesses.

Read more
Strategy·October 2024·5 min read

The hidden costs of cheap web hosting

$2/month hosting sounds like a bargain. Then you add the costs you didn't see coming. A clear-eyed look at what cheap shared hosting actually costs Australian small businesses.

Read more
Explainer·July 2024·6 min read

What is managed WordPress hosting, and do you actually need it?

Managed WordPress hosting is a term thrown around a lot, but what does it actually mean? And is it worth paying more for? An honest breakdown.

Read more
Guide·March 2024·7 min read

How to migrate your WordPress site to Australian hosting

Moving your WordPress site to a new host is simpler than most people think. A step-by-step guide to migrating without downtime, data loss, or stress.

Read more
Infrastructure·November 2023·6 min read

Why Linux is still the best environment to run WordPress

WordPress was written for Linux. Not as a preference - as a dependency. Understanding why helps you make better decisions about where and how you host your site.

Read more
Guide·September 2023·6 min read

What to look for in Australian WordPress hosting: a plain-English checklist

Australian WordPress hosting ranges from cheap shared servers to purpose-built environments. Here's a practical checklist of what actually matters — and what's marketing.

Read more
Performance·July 2023·5 min read

Why your WordPress site needs to be hosted on Australian servers

If your business serves Australian customers, your web server should be in Australia. The speed difference is significant, the SEO impact is real, and the data sovereignty argument is increasingly important.

Read more
Security·April 2023·6 min read

Why where your WordPress site runs matters as much as how you secure it

WordPress security advice focuses on plugins, passwords, and updates. But the hosting environment — isolation, PHP version, server-level protections — matters just as much, and most site owners never evaluate it.

Read more
Security·November 2022·6 min read

Why WordPress is still the most attacked CMS — and what that means for your site

WordPress powers over 43% of all websites. That dominance makes it far and away the primary target for automated attacks. Here's what that actually means — and why it doesn't mean WordPress is uniquely insecure.

Read more
Security·May 2022·5 min read

Credential stuffing: the attack your password policy alone can't stop

Credential stuffing uses leaked username and password combinations from other breaches. A strong WordPress password doesn't help if the same password was used on a site that's already been compromised.

Read more
Explainer·September 2021·5 min read

WordPress Full Site Editing explained: what it is and whether you need it

WordPress 5.8 introduced Full Site Editing — block-based control over headers, footers, and site-wide templates. Here's what it actually means for sites currently running classic themes.

Read more
Security·April 2021·5 min read

Why keeping your plugins updated is your most important WordPress security task

Plugin vulnerabilities are now the leading cause of WordPress compromises, ahead of weak passwords and outdated core. Here's why plugin updates matter more than ever — and how to manage them.

Read more
Strategy·October 2020·5 min read

Why cheap WordPress hosting gets more expensive after a hack

Budget shared hosting saves money upfront. But cleanup fees, lost traffic, and recovery time after a compromise often exceed years of the price difference with better hosting.

Read more
Guide·May 2020·6 min read

Moving your Australian business online: a WordPress checklist

Getting the fundamentals right when setting up a WordPress site for your Australian business. Domain, hosting, essential plugins, and what to launch with versus what can wait.

Read more
Security·August 2019·6 min read

WooCommerce security basics for Australian online stores

Running a WooCommerce store means handling customer payment and personal data. Here's the security baseline every Australian store should have in place before accepting a single order.

Read more
Performance·April 2019·5 min read

Why your WordPress host's PHP version matters more than you think

PHP 5.6 went end-of-life in December 2018. PHP 7.x is two to three times faster for typical WordPress workloads and receives active security updates. Many hosts still run outdated versions.

Read more
Explainer·December 2018·6 min read

Gutenberg explained: what the new WordPress editor means for your site

WordPress 5.0 ships with a completely new block-based editor. Here's what Gutenberg actually is, what changes for existing sites, and whether you need to do anything.

Read more
Compliance·March 2018·5 min read

Australia's data breach laws are now in effect: a checklist for WordPress site owners

The Notifiable Data Breaches scheme came into effect on 22 February 2018. If your WordPress site collects personal information, here's what to check and do right now.

Read more
Compliance·October 2017·6 min read

Australia's data breach notification laws: what WordPress site owners need to know

Australia's Notifiable Data Breaches scheme takes effect in February 2018. If your WordPress site collects contact details, processes orders, or stores member information, the new obligations apply to you.

Read more
Security·February 2017·6 min read

The WordPress 4.7 REST API vulnerability: what happened and what to learn

A critical unauthenticated content injection vulnerability in WordPress 4.7 was patched silently, then disclosed publicly a week later. Thousands of sites were defaced within hours. Here's the full story.

Read more
Security·December 2016·5 min read

What WordPress's REST API means for security

WordPress 4.7 enabled the REST API by default for all sites. It's a powerful addition — and a new attack surface that exposes user information and site structure publicly.

Read more
Explainer·April 2016·5 min read

WordPress.com vs WordPress.org: which is right for your Australian business?

The same name, two completely different products. The confusion between WordPress.com and WordPress.org trips up a lot of Australian small business owners making their first website decision.

Read more
Security·August 2015·6 min read

The real cost of a hacked WordPress site

Most site owners think of a hack as an inconvenience. The reality is a cascade of costs — cleanup fees, Google blacklisting, email deliverability damage, and months of SEO recovery.

Read more
Security·March 2015·5 min read

Two-factor authentication for WordPress: is it worth it?

Two-factor authentication means that even if an attacker gets your password, they still can't log in. Here's what it actually involves and where it fits in a broader security approach.

Read more
Security·September 2014·6 min read

Should your WordPress site use HTTPS?

Google announced HTTPS as a ranking signal in August 2014. SSL certificates still cost money and require configuration. Here's an honest look at whether it's worth it for a small business site.

Read more
Performance·August 2014·5 min read

Why your WordPress hosting matters more than your theme

Theme marketplaces compete on speed benchmarks run on fast servers. On an overloaded shared host, the lightest theme in the world won't help you. Server response time is the variable that matters most.

Read more
Explainer·November 2013·5 min read

WordPress automatic updates: should you let them run?

WordPress 3.7 introduced automatic background updates for minor releases. No prompts, no action required. Here's the honest case for and against — and what it actually means for your site.

Read more
Security·April 2013·6 min read

The 2013 botnet attacks on WordPress: why every site is a target

In April 2013, a coordinated botnet of over 90,000 servers launched sustained brute-force attacks against WordPress sites worldwide. Here's what happened and what changed because of it.

Read more
Security·September 2012·5 min read

Why WordPress comment spam is more than just annoying

Comment spam and trackback floods aren't just a moderation headache — they consume real server resources and can slow your site as effectively as a genuine traffic spike.

Read more
Security·April 2012·6 min read

Brute force attacks on WordPress: what's happening and how to stop them

Automated attacks on WordPress login pages escalated significantly in 2012. Here's how brute force attacks work, why WordPress is targeted, and the practical steps to stop them.

Read more
Performance·November 2011·5 min read

Why shared hosting hurts WordPress performance

Shared hosting puts your WordPress site on a server with hundreds of others. When one gets busy, yours slows down — and there's nothing you can do about it. Here's what's actually happening.

Read more
Security·August 2011·5 min read

The TimThumb vulnerability: is your WordPress theme at risk?

A tiny image-resizing script bundled into hundreds of premium WordPress themes became one of the most widely exploited vulnerabilities in WordPress history. Here's what happened and what to do.

Read more
Security·November 2010·5 min read

5 WordPress security basics every site owner should know

Most hacked WordPress sites share the same handful of problems. Five things to do for every WordPress install — none of them complicated, all of them effective.

Read more
Security·August 2010·5 min read

Why you should update WordPress the moment a new version drops

Running an old version of WordPress is one of the most common reasons sites get hacked. The gap between a security patch being released and attacks beginning is measured in hours.

Read more