BitFire security research

WordPress security research, explained.

Learn how real vulnerabilities work, what a firewall can and cannot stop, and how to write safer PHP—without needing to be a security specialist.

Developer working at a laptop with code visible on the screen
Research for the people who maintain, build, and defend WordPress.
01 · ADMINISTRATORS

For WordPress administrators

Clear remediation steps and signs that need investigation.

02 · DEVELOPERS

For PHP developers

The code path behind a flaw and patterns that make intent easier to verify.

03 · SECURITY TEAMS

For security teams

Dated methodology, explicit limitations, and links to primary sources.

Research library

Turn a finding into a practical decision.

BitFire Research turns security findings into practical decisions. Vulnerability articles begin with the update or recovery action a site owner should take. Technical sections then explain the request, authorization mistake, or protected operation for developers who want to understand the code path.

Suggest a research topic

What should we explain next?

Tell us about a confusing vulnerability, defensive claim, or PHP security pattern. Useful research starts with a practical question.

Send BitFire a topic
Protect my site free →