Skip to content

Details

This month, Austin Ginder will share the story of how a wave of malware injections led to building WP Beacon, a public scanner that watches top plugins on wordpress.org for supply chain attacks. We'll walk through real catches from the past two months, the tools built along the way, and where it all goes next.

What we'll cover:

  • The February 2026 reset โ€” 85+ sites compromised in a few weeks
  • Catching Widget Logic, a 16-year-old plugin quietly sold and weaponized
  • Why version numbers lie and hashes don't
  • CaptainCore Drift uncovering a five-year dormant backdoor
  • WP Beacon's first live catch โ€” Scroll To Top and its hidden update channel
  • How AI made forensic-level investigation possible
  • WP Registry โ€” the next step. Audit 100% of code

Bring your questions about WordPress security, AI-assisted forensics, or anything in between.

Pizza ๐Ÿ• and introductions at 7pm. Come with your laptops and join the discussion. RSVP here or on LocalMeet.

๐Ÿ—’๏ธ About our location

Related topics

Sponsors

Woo

Woo

Woo is the leading open-source ecommerce platform, built on WordPress.

Jetpack

Jetpack

Safer, faster WordPress.

WordPress com

WordPress com

We're a hosted version of the open-source software

Hostinger

Hostinger

Helping people build their online presence

You may also like