{"id":11624,"date":"2026-07-29T18:30:00","date_gmt":"2026-07-29T13:00:00","guid":{"rendered":"https:\/\/4ksamachar.com\/?p=11624"},"modified":"2026-07-29T18:30:00","modified_gmt":"2026-07-29T13:00:00","slug":"wptavern-227-maciek-palmowski-on-testing-secure-wordpress-hosting-does-the-marketing-match-reality","status":"publish","type":"post","link":"https:\/\/4ksamachar.com\/?p=11624","title":{"rendered":"WPTavern: #227 \u2013 Maciek Palmowski\u00a0on Testing Secure WordPress Hosting: Does the Marketing Match Reality?"},"content":{"rendered":"<details>Transcript<\/p>\n<div>\n<p class=\"wp-block-paragraph\">[00:00:19] <strong>Nathan Wrigley:<\/strong> Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley.<\/p>\n<p class=\"wp-block-paragraph\">Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in this case, testing secure WordPress hosting, does the marketing match the reality?<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019d like to subscribe to the podcast, you can do that by searching for WP Tavern in your podcast player of choice, or by going to wptavern.com\/feed\/podcast, and you can copy that URL into most podcast players.<\/p>\n<p class=\"wp-block-paragraph\">If you have a topic that you\u2019d like us to feature on the podcast, I\u2019m keen to hear from you and hopefully get you, or your idea, featured on the show. Head to wptavern.com\/contact\/jukebox, and use the form there.<\/p>\n<p class=\"wp-block-paragraph\">So on the podcast today we have Maciek Palmowski. Maciek is based in Poland and works at Patchstack, one of the companies in the WordPress ecosystem dedicated specifically to security. At Patchstack, Maciek collaborates with other security professionals on industry reports, bug bounty programmes, and solutions for agencies, product owners, and hosting companies aiming to secure their client sites.<\/p>\n<p class=\"wp-block-paragraph\">I met up with Maciek at WordCamp Europe, and we discussed his presentation there. It examined the claims of secure hosting made by many WordPress hosting providers. He describes how Patchstack set out to test these claims with real world penetration testing, using 30 known plugin vulnerabilities across multiple hosts. Employing standardised methodologies and validating their results independently.<\/p>\n<p class=\"wp-block-paragraph\">The findings are sobering. The majority of WordPress specific attacks still get through, and there\u2019s a significant gap between the marketing hype and real protection.<\/p>\n<p class=\"wp-block-paragraph\">The conversation starts with Maciek\u2019s background, and how his journey in the WordPress security space led to a focus on the promises made by hosts.<\/p>\n<p class=\"wp-block-paragraph\">From there, the discussion gets into the research approach, the selection of well-known vulnerabilities, consistent testing across different hosting environments, and the surprising result that even hosts with identical security tooling produce drastically different outcomes, showing it\u2019s not just about the tools you use, but how you use them.<\/p>\n<p class=\"wp-block-paragraph\">We talk about the Swiss cheese model of security, every layer will have holes, so you need multiple overlapping defences, and honest communication from hosts about their limitations.<\/p>\n<p class=\"wp-block-paragraph\">We also explored whether an industry-wide standard, or badge, for secure hosting is feasible or even desirable, given how easy it is for strong marketing claims to outpace reality.<\/p>\n<p class=\"wp-block-paragraph\">AI also enters the conversation, increasing both the speed and sophistication of attacks, and making patching, and processes, even more important, especially as the volume of vulnerabilities continues to rise and the time to exploitation drops.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019re interested in understanding what secure hosting really means, how to ask intelligent questions of providers, and the realities of WordPress security in 2026, this episode is for you.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019d like to find out more, you can find all of the links in the show notes by heading to wptavern.com\/podcast, where you\u2019ll find all the other episodes as well.<\/p>\n<p class=\"wp-block-paragraph\">And so without further delay, I bring you Maciek Palmowski.<\/p>\n<p class=\"wp-block-paragraph\">[00:03:56] <strong>Maciek Palmowski:<\/strong> I am joined on the podcast by Maciek Palmowski. Hello Maciek.<\/p>\n<p class=\"wp-block-paragraph\">Perfect. You did great.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:01] <strong>Nathan Wrigley:<\/strong> For some reason, your name has got into my head. A lot of the people that I interview, I struggle with their name, and I continue to struggle, but for some reason, I established many years ago that was how to say your name. And I think I\u2019ve done it correctly ever since then.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:16] <strong>Maciek Palmowski:<\/strong> Yes you did. You\u2019re almost having the typical Polish accent, so you\u2019re doing great.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:21] <strong>Nathan Wrigley:<\/strong> So we are at WordCamp Europe, which is in Krakow, or Krakow, I don\u2019t know how.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:26] <strong>Maciek Palmowski:<\/strong> Krakow.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:27] <strong>Nathan Wrigley:<\/strong> Thank you, that was good. And the reason Maciek is correcting my pronunciation is because Maciek is actually from Poland, which I suppose means that this is a bit of a, well, it\u2019s like a home game to you.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:37] <strong>Maciek Palmowski:<\/strong> In a way so, but it\u2019s also like a bit of a shame because I do like travelling when WordCamp Europe\u2019s are happening. And, you know, just hopping on the train and going to Krakow, it was like a, I mean it\u2019s cool because, yeah, the venue\u2019s amazing, everything is great, but still I\u2019m staying home, so yeah.<\/p>\n<p class=\"wp-block-paragraph\">[00:04:53] <strong>Nathan Wrigley:<\/strong> Yeah, mixed feelings. So Maciek has done, or is going to do a presentation at WordCamp EU. Have you done it yet?<\/p>\n<p class=\"wp-block-paragraph\">[00:05:02] <strong>Maciek Palmowski:<\/strong> I will do it tomorrow.<\/p>\n<p class=\"wp-block-paragraph\">[00:05:04] <strong>Nathan Wrigley:<\/strong> Okay. And are you all set, are you one of these like really prepared people that has all the slides done, or are you last minute?<\/p>\n<p class=\"wp-block-paragraph\">[00:05:11] <strong>Maciek Palmowski:<\/strong> Everything is ready. I already did one version of it at the Checkout Summit in Palermo, so.<\/p>\n<p class=\"wp-block-paragraph\">[00:05:17] <strong>Nathan Wrigley:<\/strong> Oh I see. So you\u2019ve had a sort of dry run of elsewhere.<\/p>\n<p class=\"wp-block-paragraph\">[00:05:19] <strong>Maciek Palmowski:<\/strong> Of course.<\/p>\n<p class=\"wp-block-paragraph\">[00:05:20] <strong>Nathan Wrigley:<\/strong> Excellent. So the presentation, which is going to be the focus of today\u2019s conversation, is called Testing the promise, does secure hosting deliver? And I may as well read the blurb because it was a reasonably short one.<\/p>\n<p class=\"wp-block-paragraph\">So it says, secure hosting, in quotes, is everywhere in WordPress. What does it actually protect against? We put this claim to the test with real penetration testing. 30 known vulnerabilities, multiple hosting providers, standardised methodology, validated by independent observers. The findings reveal a critical gap between marketing and reality. WordPress specific attacks succeed most of the time. That\u2019s quite an alarming sentence. This talk shares the complete results and explains why generic security fails.<\/p>\n<p class=\"wp-block-paragraph\">So, we\u2019ll get into that in a moment. But as with all people, when I\u2019m talking to them about security, I guess it\u2019s good to establish who you are, and what your credentials are and what you\u2019ve done, and how is it that you get to talk about security with authority. So over to you really, a little moment to give us your bio and tell us about you.<\/p>\n<p class=\"wp-block-paragraph\">[00:06:20] <strong>Maciek Palmowski:<\/strong> Okay. So I work at Patchstack, and Patchstack is one of those few companies in WordPress space that are doing a lot in terms of security. We are constantly running this bug bounty for the whole ecosystem. We have quite a few solutions for both clients and hosting companies, and I work there right now. My role is, if I remember, the Growth Team Engineer, something like this.<\/p>\n<p class=\"wp-block-paragraph\">But yeah, I do spend a lot of time working with other security people. So when we are working on all the reports, when we are checking the data, I\u2019m also part of those teams that are working on it. So yeah, I think I know a thing or two about what is happening behind the scenes when it comes to WordPress security.<\/p>\n<p class=\"wp-block-paragraph\">[00:07:02] <strong>Nathan Wrigley:<\/strong> Yeah, thank you. Always good to get that established though, right at the outset.<\/p>\n<p class=\"wp-block-paragraph\">Patchstack is a company which is not a host though, I suppose that\u2019s important to mention at the beginning. It\u2019s a company which is in the security space, very much in the WordPress space, but perhaps more broad than WordPress, I\u2019m not sure. But not a hosting company.<\/p>\n<p class=\"wp-block-paragraph\">But obviously your presentation focuses its aim on hosting, I guess because that\u2019s one of the places where the claim about security is most often made. You know, you\u2019ll go to a, the landing page of hosting Company X, and you\u2019ll see somewhere fairly near the top, secure hosting, or something along those lines. And you\u2019ve decided to examine that in fine detail and look at these 30 vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">I guess really just tell us about this test and what it is that you decided to do and some of the items that came out of that.<\/p>\n<p class=\"wp-block-paragraph\">[00:07:50] <strong>Maciek Palmowski:<\/strong> Okay, so maybe let\u2019s start with how it even started, right? Because there was a trigger. At some point we published one report about the state of WordPress security. We tweeted about this. We got the response from none other than Matt Mullenweg, who kind of asked a very interesting question, but isn\u2019t hosting companies taking care of this already?<\/p>\n<p class=\"wp-block-paragraph\">And this was, kind of at this moment when we were, we thought that we know the answer that, no they aren\u2019t. But to be honest, we didn\u2019t have any broader proof about this.<\/p>\n<p class=\"wp-block-paragraph\">We knew how it\u2019s working at some hosting companies, but we could say that it was more of an anecdotal evidence that we had. So this was kind of the trigger that made us, okay, let\u2019s check this. But not with one partner or two partners, but with more hosting companies.<\/p>\n<p class=\"wp-block-paragraph\">So we did this research twice. First we just did kind of a beta run because we weren\u2019t sure about the result and, is it even a good idea to go deeper inside of it? And during our first run, we were already very surprised because like the methodology was very simple. We just installed vulnerable plugins and we checked if we would be able to use the vulnerability. Because if the hosting is claiming that, we got your back, we are making your website secure, we have this and that, this means that they should protect against it. So it was as simple as that.<\/p>\n<p class=\"wp-block-paragraph\">And when we were doing our first test, we were quite surprised because we saw, if I remember, that 80% of the attacks went through. 80% of the attacks. So our first reaction was, okay, we are doing something wrong. Okay, this was only few hosting companies, less plugins, but still the result were so surprising for us because we thought that, okay, that the problem exists, but it\u2019s not that big of a problem. But it was.<\/p>\n<p class=\"wp-block-paragraph\">So that\u2019s why we did the second test. And this is about which the, my talk will be mostly when we tested more hosting companies, more plugins. And we saw that the problem still exists.<\/p>\n<p class=\"wp-block-paragraph\">Of course it was, in some cases 70 few percent. So still, it\u2019s a huge problem, especially if we are talking about some companies that are literally saying, you don\u2019t have to install anything additional when it comes to security on your website. We got your back. They don\u2019t. We found a lot of interesting things, but still the problem exists.<\/p>\n<p class=\"wp-block-paragraph\">[00:10:21] <strong>Nathan Wrigley:<\/strong> So just deep diving into that a little bit, when tests like this are done, there\u2019s obviously, the claim might be levelled, you know, obviously Patchstack would, this kind of maybe benefits Patchstack, if you know what I mean.<\/p>\n<p class=\"wp-block-paragraph\">So let\u2019s just sort of clear up what the test involved. So presumably the plugins that you chose are ones where it\u2019s publicly known that there\u2019s a vulnerability in this component or this particular file or what have you. So is that the case? This is stuff that, longstanding understanding that there\u2019s a problem here.<\/p>\n<p class=\"wp-block-paragraph\">[00:10:51] <strong>Maciek Palmowski:<\/strong> Yes. We only use the plugins that we had all the proof of concepts. So we know how have the vulnerability happened, what was the attack vector? They were all reported through our bug bounty programme, because that\u2019s why we had the proof of concept. Yeah, and that\u2019s it.<\/p>\n<p class=\"wp-block-paragraph\">It was, like I said, it was as simple as that. We had a really broad mix of all the plugins. How many? It was 30 something of those plugins, if I remember. Different ones. Some were connected with WooCommerce. So, like a very broad selection of them. Different vulnerability types. So we try to mix it up as much as possible.<\/p>\n<p class=\"wp-block-paragraph\">[00:11:27] <strong>Nathan Wrigley:<\/strong> Was the situation for each hosting company the same though? In other words, was the things that you did in one hosting environment the exact same as you did in another hosting environment? No. You mixed that up a bit as well.<\/p>\n<p class=\"wp-block-paragraph\">[00:11:38] <strong>Maciek Palmowski:<\/strong> I mean we used all the same plugins, like the methodology was always the same. But we got totally different results. Even if, and this was one of the most interesting findings, because very often hostings will put a logo of some company that takes care of security. For example, say, Cloudflare. And despite using the same stack for security, they got different results.<\/p>\n<p class=\"wp-block-paragraph\">[00:12:02] <strong>Nathan Wrigley:<\/strong> Interesting.<\/p>\n<p class=\"wp-block-paragraph\">[00:12:03] <strong>Maciek Palmowski:<\/strong> So it turns out, in many cases, it\u2019s not about the tools that you are using, it\u2019s how you are using them, which was very interesting. And we did everything. We tried to enable every feature, every security features on those hosting, to kind of give them a chance to kind of make sure that they are defending the most as they can.<\/p>\n<p class=\"wp-block-paragraph\">And the result in most cases was very simple. They were doing quite well with the generic ones like uploads, patch reversal, things like this, which are very generic in PHP. But with those WordPress specific attacks, they just failed miserably.<\/p>\n<p class=\"wp-block-paragraph\">[00:12:44] <strong>Nathan Wrigley:<\/strong> That\u2019s so interesting. The word secure hosting, which you\u2019ll see all over the place, it feels a bit like using the word healthy on food. There\u2019s no real definition of what healthy is. You know, a company selling chocolate could probably pretend that it\u2019s healthy compared to something else.<\/p>\n<p class=\"wp-block-paragraph\">[00:13:04] <strong>Maciek Palmowski:<\/strong> Like here, healthy chocolate is exactly, like in some cases secure hosting.<\/p>\n<p class=\"wp-block-paragraph\">[00:13:07] <strong>Nathan Wrigley:<\/strong> Right. So what do you take from this then? I mean basically, is your survey saying that whenever you see the word secure hosting, be sceptical?<\/p>\n<p class=\"wp-block-paragraph\">[00:13:16] <strong>Maciek Palmowski:<\/strong> Yes.<\/p>\n<p class=\"wp-block-paragraph\">[00:13:16] <strong>Nathan Wrigley:<\/strong> Okay. As simple as that.<\/p>\n<p class=\"wp-block-paragraph\">[00:13:18] <strong>Maciek Palmowski:<\/strong> It\u2019s as simple as that. Because one of the things that we were always promoting, security is not a plugin, it\u2019s not a one button thing. Security is a process. It\u2019s layers.<\/p>\n<p class=\"wp-block-paragraph\">And that\u2019s kind of why we, especially after this report starting kind of using the term, Swiss cheese layer model. Because every layer will fail in some way. That\u2019s also why you still need all the security solutions that hosting provides, because they do have a lot of interesting solutions against those generic attacks.<\/p>\n<p class=\"wp-block-paragraph\">Because they\u2019re doing really great when it comes to those generic ones. And that\u2019s great because some of the attacks will be already dealt with. So whatever passes to the second layer, it has less work to do because a lot of it was already stopped at the first layer. The second layer should be something more WordPress specific that understand what is installed. And with this it can catch also a lot of it.<\/p>\n<p class=\"wp-block-paragraph\">But still, you have to be prepared that, because again, this layer also isn\u2019t perfect. Because there are zero days vulnerabilities, there are custom code, there are a lot of things that can happen, that your website will be hacked. I mean, weak password. Simple as that. That\u2019s why you also need to have a layer, which will be more of what to do if everything else fails. Because you do need to know that you have to inform your clients, all the GDPR related things. How to kind of, I don\u2019t know, use the backups.<\/p>\n<p class=\"wp-block-paragraph\">In short you need to have procedures. You have to be prepared before the attack happens. Because let\u2019s be honest, asking some lawyers about, what should we send to our clients? The moment when, well, the milk is already spilled. It\u2019s like the worst moment to think about it. Especially that, hey, your website was just hacked. It\u2019s not just a technical problem, it\u2019s also a business problem. Again, with those GDPRs and everything.<\/p>\n<p class=\"wp-block-paragraph\">So yeah, the more layers, the better. You still need to remember, every layer can fail in some place. That\u2019s why the more, the better.<\/p>\n<p class=\"wp-block-paragraph\">[00:15:29] <strong>Nathan Wrigley:<\/strong> Would you like to see a standard industry-wide definition of something like a badge or, I don\u2019t know, let\u2019s say for example, that you put the word secure hosting on your website, that has to actually stand for something.<\/p>\n<p class=\"wp-block-paragraph\">Because obviously coming from the background that you do with a broad oversight on what that is, you have a vast amount of data at your disposal. You can see all of this kind of stuff. But every company can make the claim that our food is healthy, our hosting is secure. But I don\u2019t know, in the model that we\u2019ve got where any company can put anything they like on a website, I don\u2019t really know how you do that, but some sort of accreditation or something. I don\u2019t know.<\/p>\n<p class=\"wp-block-paragraph\">[00:16:08] <strong>Maciek Palmowski:<\/strong> Honestly, it\u2019s really difficult because as I said before, a lot of companies using the same tools were failing in different ways. So that\u2019s a problem. On the other hand, like sometimes the, those stupid things like weak passwords. And it doesn\u2019t matter that you had a, let\u2019s call it a certified secure hosting, you still failed because your password was weak, you know? So, also certificates like this can backfire because some people might think I have a secure hosting, I don\u2019t have to worry about things. And then you have 10 admin accounts for everyone.<\/p>\n<p class=\"wp-block-paragraph\">[00:16:43] <strong>Nathan Wrigley:<\/strong> Is there is there something, some mark of that description that you, personally, that you go looking for though? Is there some credentialing system which you think actually does carry some weight? So for example, I don\u2019t know, like the insurance space or the accountancy space or something like that. You have to have that accreditation in order to do business. Is there something like that? Is there a mark which hosting companies can apply for which you could have some confidence in it?<\/p>\n<p class=\"wp-block-paragraph\">[00:17:13] <strong>Maciek Palmowski:<\/strong> Okay. So for sure one of those things would be, and I don\u2019t want to say it as an advertisement, but it is a thing that you see that the hosting is thinking a bit better about security, kind of looking if they are a Patchstack partner. Because this kind of automatically means that they do have this WordPress, the security WordPress layer. So that\u2019s already a good sign.<\/p>\n<p class=\"wp-block-paragraph\">So yeah, I would start with this. I think that\u2019s kind of one of the simplest ways, but again, Patchstack isn\u2019t the only solution that does it. So looking for partners of such companies might be the best way to start because having those Patchstack aware security solutions built in, into the hosting is a really good sign.<\/p>\n<p class=\"wp-block-paragraph\">[00:18:05] <strong>Nathan Wrigley:<\/strong> Yeah, okay. Now, the inevitable conversation in the year 2026 is AI. It doesn\u2019t matter which area of WordPress you\u2019re talking about. AI manages to get in somewhere. I am presuming that the landscape in terms of security only got more complicated because of AI. Because I\u2019m imagining that attacks that needed to be conceived by a human can now be conceived in a fraction of the time by an AI agent. But not just one, maybe a dozen or a thousand or whatever it may be.<\/p>\n<p class=\"wp-block-paragraph\">Let\u2019s just talk about that for a moment. It feels almost as if AI and security are like, that\u2019s a real systemic problem for the future of the entire industry. Because these things can happen so fast, a plugin vulnerability is discovered by an AI agent. It then discovers the attack surface, implements the attack all in a matter of seconds, possibly. What\u2019s the position? Like, how do we stay calm basically in the year 2026?<\/p>\n<p class=\"wp-block-paragraph\">[00:19:09] <strong>Maciek Palmowski:<\/strong> So the problem already existed around a year ago, because a year ago when we did our State of WordPress Security Report, we already saw that vulnerabilities are being used after around five hours after kind of being published. So five hours. That\u2019s the first thing, because we still have a lot of people that say, yeah, just update your WordPress weekly and you\u2019re good to go. No, you\u2019re not. Looking at this number, you have five hours.<\/p>\n<p class=\"wp-block-paragraph\">[00:19:39] <strong>Nathan Wrigley:<\/strong> Okay. Let\u2019s just parse that at the moment. So the vulnerability is published. So there\u2019s a whole thing there, like the vulnerability may well have been discovered prior to being published, so that\u2019s a whole other thing.<\/p>\n<p class=\"wp-block-paragraph\">[00:19:52] <strong>Maciek Palmowski:<\/strong> So first the vulnerability is discovered. Then at least how it works on, with our bug bounty. We inform the vendor they have, let\u2019s say around a month to fix it. When they fix it, we publish everything and, yeah.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:09] <strong>Nathan Wrigley:<\/strong> Okay, so from the moment you publish, you can then detect that that is being leveraged within a space of five hours.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:17] <strong>Maciek Palmowski:<\/strong> Yes.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:17] <strong>Nathan Wrigley:<\/strong> Okay, that\u2019s really interesting.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:19] <strong>Maciek Palmowski:<\/strong> But there is a problem. There is a really big problem. So if the vendor doesn\u2019t respond, we still publish it.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:26] <strong>Nathan Wrigley:<\/strong> How long do you give them? Is it like.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:27] <strong>Maciek Palmowski:<\/strong> It is the one month.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:28] <strong>Nathan Wrigley:<\/strong> Okay, thirty days.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:30] <strong>Maciek Palmowski:<\/strong> Of course, if they reach out that there is some problem, they need like extra days. But in most cases, we\u2019re talking about the vendors that just don\u2019t respond at all. We publish it anyway.<\/p>\n<p class=\"wp-block-paragraph\">But the problem is that, from all the vulnerabilities that were discovered last year, 50% weren\u2019t patched at the moment of publishing about it. 50%.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:50] <strong>Nathan Wrigley:<\/strong> So half of the plugins where there was a known vulnerability, the vendor had been informed, they\u2019d had this 30 day window. Half of them made no amendment to their code.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:01] <strong>Maciek Palmowski:<\/strong> Exactly.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:02] <strong>Nathan Wrigley:<\/strong> Okay. Wow, okay.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:03] <strong>Maciek Palmowski:<\/strong> Again, going back to this classical, yeah, just update your WordPress regularly. No.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:08] <strong>Nathan Wrigley:<\/strong> No, that\u2019s a really different surface, isn\u2019t it?<\/p>\n<p class=\"wp-block-paragraph\">[00:21:11] <strong>Maciek Palmowski:<\/strong> It doesn\u2019t work on so many levels. Because not only the problem is with the fact that, still the famous five hours, which also, it\u2019s five hours now. It was much longer a few years ago. On the other hand, yeah, most of those, I mean around half of it aren\u2019t patched, so the attacks will happen quicker than it get patched. So yeah, there is a lot of problems like this. And also the problem with security is that it\u2019s really difficult to sell.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:39] <strong>Nathan Wrigley:<\/strong> It\u2019s like insurance, isn\u2019t it?<\/p>\n<p class=\"wp-block-paragraph\">[00:21:40] <strong>Maciek Palmowski:<\/strong> Yeah. But insurance, okay, you see your car, your house, it\u2019s real. It\u2019s real, you kind of see it. The only category of websites that it\u2019s much easier to kind of explain is e-commerce.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:54] <strong>Nathan Wrigley:<\/strong> Yes. You can feel the tightening on your wallet.<\/p>\n<p class=\"wp-block-paragraph\">[00:21:56] <strong>Maciek Palmowski:<\/strong> They literally see the money. They can kind of really, okay, one hour of my website not working equals this and this Z\u0142otys or Euros or whatever. So that\u2019s easier to explain. But for most people, yeah, security, meh.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:11] <strong>Nathan Wrigley:<\/strong> Yeah. That\u2019s really interesting. So you mentioned, about this survey, you mentioned that fully 80% of your penetration testing resulted in something. What were the sort of, the high level items? Apart from that 80% figure. What were some of the other, because you said there were a few interesting things that dropped out of it. Can you mention anything else?<\/p>\n<p class=\"wp-block-paragraph\">[00:22:31] <strong>Maciek Palmowski:<\/strong> So like I said, one of the things was that we learned that, despite using the same tools, we got different results. That was also a surprise for us.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:39] <strong>Nathan Wrigley:<\/strong> So let\u2019s just figure that out. So at hosting company A, we\u2019ve got a WordPress website with the same collection of plugins in. Hosting company B, exactly the same as far as you can make it the same, but things are different.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:52] <strong>Maciek Palmowski:<\/strong> No, no, they are, for example, they\u2019re using for security the same tools.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:56] <strong>Nathan Wrigley:<\/strong> Right, okay.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:57] <strong>Maciek Palmowski:<\/strong> So in theory, if they\u2019re using the same tools, we should have exactly the same results.<\/p>\n<p class=\"wp-block-paragraph\">[00:23:03] <strong>Nathan Wrigley:<\/strong> So does that then point to a different set of configurations on the backend, or is it more curious than that? You just don\u2019t quite know what\u2019s going on.<\/p>\n<p class=\"wp-block-paragraph\">[00:23:12] <strong>Maciek Palmowski:<\/strong> I mean because it\u2019s not something that they will tell us. But yeah, in most cases, it\u2019s all about configuration because the fact that you\u2019re using a tool, it\u2019s also important how you use a tool.<\/p>\n<p class=\"wp-block-paragraph\">Also, with security is very often about, is something easy to use or is something secure? And kind of finding the balance. So some of the companies probably had a bit more aggressive configuration, which is better from the security point of view, but probably more often result in some annoying side effects for the user.<\/p>\n<p class=\"wp-block-paragraph\">Also what, this was one of the most interesting things, but also what was very interesting because we contacted every company afterwards and we informed them that we did the test. Here are the results, what went through, what was blocked. And some of the companies did an amazing job of fixing whatever they could. On the other hand, we saw that some of the companies, because we did some extra tests later just to check what they did with our report, did nothing.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s one of the things about security in general, not about the hosting, about even having vulnerability in your plugin. That\u2019s normal that we make mistakes. We\u2019re humans, right? So that\u2019s normal. What\u2019s important is how we deal with them. If you have a problem and you fix it as quickly as possible, as good as possible, that\u2019s great because you learn from your mistakes, you fix it, and you move on. Perfect. Good job. Now you are in a much better position than before. But if you get this, you look at it and you say, ah, this is fine, that\u2019s the worst behaviour from the security point of view that you can have.<\/p>\n<p class=\"wp-block-paragraph\">[00:24:57] <strong>Nathan Wrigley:<\/strong> I\u2019m going to ask you not to name names here, but were some of the companies familiar to us?<\/p>\n<p class=\"wp-block-paragraph\">[00:25:05] <strong>Maciek Palmowski:<\/strong> For sure, because we did test the biggest ones. But there is a reason why we didn\u2019t want to name them, and it wasn\u2019t about that we were afraid that I know someone will get mad or whatever. It was more about this weird side effect that could happen.<\/p>\n<p class=\"wp-block-paragraph\">Some users would think, my hosting isn\u2019t on this list, so probably I\u2019m secure. Probably you\u2019re not, you just weren\u2019t in the test. Because we also did some site checks and everything. And we saw that a lot of those problems happen at most of the hosting companies. And like I said, the more important part was how did they reacted after getting the report. Like I said, it was a more common problem that we even thought.<\/p>\n<p class=\"wp-block-paragraph\">[00:25:43] <strong>Nathan Wrigley:<\/strong> Do you, obviously, you know, caveat all of this with the fact that you work for Patchstack and what have you, do you see it even as the role of a hosting company to have any position on security publicly? Or would you prefer them not to make grand claims about things that you believe they can\u2019t necessarily substantiate?<\/p>\n<p class=\"wp-block-paragraph\">I don\u2019t really know where I\u2019m going with that question, but I\u2019m just wondering if there\u2019s just a sense that the language that\u2019s being used is too strong. You know, secure hosting implies we\u2019ve got all the padlocks, and the padlocks are there and you\u2019ve got nothing to worry about. You\u2019ve found a different picture. So I\u2019m just wondering whether or not you would just prefer that the hosting companies stop talking about this altogether.<\/p>\n<p class=\"wp-block-paragraph\">[00:26:27] <strong>Maciek Palmowski:<\/strong> I do think that\u2019s, one of the biggest problem here is about the claims, the bold claims, the whole marketing around it. Sometimes even you can find documentation of some of them that, yeah, you don\u2019t need to install any third party tool because we got you covered. We checked it, no they didn\u2019t. So that\u2019s kind of the problem.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s really more about the, how they market it. If they would say, okay, so we have a really performant hosting that does this, this and this. When it comes to security, kind of do it yourself. I mean we are providing this layer, but the rest is up to you. And that\u2019s okay. That\u2019s an honest claim. We are not doing everything for you. We are doing this part, but this is up to you. This would be much better.<\/p>\n<p class=\"wp-block-paragraph\">I know that from the marketing point of view, it doesn\u2019t sound as good as, we got all the security that you can imagine, don\u2019t have to worry about this. Because that\u2019s kind of the thing that very often managed hosts trying to sell, that you don\u2019t have to worry about things. You just have to focus on whatever you have, writing content, selling stuff. If you have a e-commerce, whatever, that\u2019s it. That\u2019s kind of the only thing you should think of. Not about performance, because we got your back. Not about security, again, we got your back. And if you are paying for a managed hosting and suddenly they would start having like this different way of messaging to, it\u2019s not that obvious that we have your back in everything. That would be very difficult for them.<\/p>\n<p class=\"wp-block-paragraph\">So now it\u2019s kind of the problem that, because everyone is kind of using this messaging, everyone else also has to. And also if we think about how a lot of those algorithms, look like that algorithms love bold claims. They want something white or black, not grey. And the truth is, most of the things we are talking about, it doesn\u2019t matter, security, SEO performance, it\u2019s everything in the grey zone. That\u2019s why a lot of developers can end their talk with, yeah, it depends. There is no right or wrong. It depends because there are so many things you have to think about.<\/p>\n<p class=\"wp-block-paragraph\">I could say that, and this is my kind of thing that, most of the websites that people have should be static. They don\u2019t need even WordPress at all. This is a horrible claim if you\u2019re a manager of a WordPress hosting, right? So that\u2019s the thing. But it all depends on so many things, but yeah, the messaging is important.<\/p>\n<p class=\"wp-block-paragraph\">[00:29:08] <strong>Nathan Wrigley:<\/strong> Yeah, if you were, on a personal level, if you were going out there looking and let\u2019s say, if you can somehow put your job hat to one side, what would be the kind of things that you would be looking for? What questions would you be asking related to security if you were to be going to these companies?<\/p>\n<p class=\"wp-block-paragraph\">From everything that you said, obviously it\u2019s not black, it\u2019s not white, it\u2019s definitely grey. So every setup has some way of being vulnerable. But what are the kind of intelligent questions that you would be bringing to hosts to get some reassurance that at least they appear to know what they\u2019re doing, even if they can\u2019t make the claim that they\u2019re a hundred percent cast iron, water tight? What might be some intelligent questions to start asking?<\/p>\n<p class=\"wp-block-paragraph\">[00:29:49] <strong>Maciek Palmowski:<\/strong> One of the best questions you can ask is just, is there any solution in your security stack that is WordPress aware? Not the general one. Because if they only start talking about some web firewall, things like this, it\u2019s already kind of a red flag. Because this is, overall, if we\u2019re talking about firewalls, that\u2019s not the correct layer about which, this is the generic one.<\/p>\n<p class=\"wp-block-paragraph\">So this is the main question. How do you take care of WordPress specific attacks? Simple question. And if they will start responding, yeah, that we have this web application firewall that, in most cases this will be a sign that, no, we are not talking about the correct layer. That\u2019s not it. It\u2019s probably not aware about what is happening in WordPress.<\/p>\n<p class=\"wp-block-paragraph\">[00:30:40] <strong>Nathan Wrigley:<\/strong> Okay. So given that this is a WordPress podcast, and we are at a WordPress event, that would be the beginning of your questioning is demonstrate that something in your stack is specific to WordPress.<\/p>\n<p class=\"wp-block-paragraph\">[00:30:52] <strong>Maciek Palmowski:<\/strong> Exactly.<\/p>\n<p class=\"wp-block-paragraph\">[00:30:53] <strong>Nathan Wrigley:<\/strong> Okay. And beyond that, is there any questions that, so let\u2019s imagine that they come back with, yes, we have something specific, it\u2019s WordPress. What would be sort of sensible follow up questions?<\/p>\n<p class=\"wp-block-paragraph\">[00:31:00] <strong>Maciek Palmowski:<\/strong> I mean you can kind of start off about, okay, what exactly you are using? Because there is a limited amount of tools that are really WordPress aware. So if they will answer with kind of a product name, that\u2019s kind of the easy way that then you can check it on your own. But that\u2019s kind of the thing. Is it WordPress aware?<\/p>\n<p class=\"wp-block-paragraph\">[00:31:19] <strong>Nathan Wrigley:<\/strong> Does it worry you in some way that there\u2019s this perception out there that WordPress is insecure? You know, if you ask a thousand people, you\u2019d maybe get 800 saying, oh WordPress, you know, we\u2019re not touching that with a barge pole.<\/p>\n<p class=\"wp-block-paragraph\">Do you worry that content like this, that you are putting out, that that might fuel that fire? Does it concern you in any way that it might lean into the argument that, I don\u2019t know, somebody can link to that blog post from a rival CMS, or a SaaS platform, which does something similar to WordPress? Where do you sit on that?<\/p>\n<p class=\"wp-block-paragraph\">[00:31:51] <strong>Maciek Palmowski:<\/strong> That\u2019s a really difficult question. And this is one of the questions that when I talk on non WordPress events, I love to ask people. Is WordPress secure? And in most cases, I see that most of the room is, yes, it\u2019s unsecure for sure. And I\u2019m like, no, that\u2019s not true. WordPress is secure. Every year there is just a few minor vulnerabilities in Core. That\u2019s it. The problem is, of course, that WordPress on its own lacks some functionality. That\u2019s why we install plugins.<\/p>\n<p class=\"wp-block-paragraph\">And here we enter another problem because, okay, every year we have like thousands of those vulnerabilities in general in plugins. On the other hand, we have thousands of plugins. So kind of statistics will always look bad. But that\u2019s why every time when you want to select a new plugin, you need to do some research. Yeah, I know it\u2019s boring and everything but, hey, now we have AI, you can do it much quicker. It can help you a lot.<\/p>\n<p class=\"wp-block-paragraph\">But looking at all those databases, for example, we have one database, WPScan has. There are those databases of WordPress vulnerabilities that occur to every plugin. And you can see, is the plugin you\u2019re interested in had a lot of vulnerabilities? On the other hand, how it kind of looked historically. It\u2019s not just about the number of them. In general, it requires some research.<\/p>\n<p class=\"wp-block-paragraph\">And yeah, if we are just like looking at this, and this kind of vibe that right now we have that we are just about really bold opinions stated quickly that will fit one TikTok, yeah, WordPress is in a horrible position because, let\u2019s be honest, it\u2019s like, if you have, I\u2019m not sure how many seconds does a TikTok movie has?<\/p>\n<p class=\"wp-block-paragraph\">[00:33:39] <strong>Nathan Wrigley:<\/strong> I think 30.<\/p>\n<p class=\"wp-block-paragraph\">[00:33:40] <strong>Maciek Palmowski:<\/strong> Okay, let\u2019s say 30. So it will sound much better that you will say, yeah, WordPress is unsecure, which is not entirely true because it depends again. One of the most boring, especially again for those algorithms and everything, it\u2019s a grey zone.<\/p>\n<p class=\"wp-block-paragraph\">Because we are collaborating with a lot of companies that are making plugins, and we see how their security flow looks like. How they are dealing with vulnerabilies that are discovered. And honestly, I\u2019m amazed how well some of those companies are doing it. They are very serious about it. They understand how important it is. For them it\u2019s something very important.<\/p>\n<p class=\"wp-block-paragraph\">[00:34:22] <strong>Nathan Wrigley:<\/strong> I suppose WordPress is a victim of its own success in that sense. And it would be a bit like, I guess a good analogy might be if you\u2019ve got a car manufacturer and they produce a thousand cars a year and you compare them to Ford who make, let\u2019s say, I don\u2019t know, 20 million a year. And the question is, well, whose cars break down more often?<\/p>\n<p class=\"wp-block-paragraph\">[00:34:41] <strong>Maciek Palmowski:<\/strong> Yeah. Do we look at the percentage of the number?<\/p>\n<p class=\"wp-block-paragraph\">[00:34:44] <strong>Nathan Wrigley:<\/strong> Right. And if you say, well, 400,000 Fords broke down last year, and one of these other manufacturer, you can immediately see why there\u2019s a problem there. And that I think is the landscape in which WordPress is often painted. The reason there\u2019s lots of publications like yours bringing out WordPress information is because it\u2019s the most popular thing. It makes sense to write about the most popular thing and to try to find the vulnerabilities and disclose them in a sensible way. So I don\u2019t know what we do with that. It is just the way it is.<\/p>\n<p class=\"wp-block-paragraph\">[00:35:15] <strong>Maciek Palmowski:<\/strong> I would also say there is one more interesting aspect because WordPress is considered unsecure because of the plugins. But what\u2019s funny, for example, Elementor is also considered unsecure because there are plugins for Elementor. This is a very weird moment when the thing that brought WordPress to its bigger success, security wise, is its biggest problem right now.<\/p>\n<p class=\"wp-block-paragraph\">Because WordPress did a lot of, I mean it was always great to, being as it\u2019s kind of, let\u2019s call it entry level CMS. For many people, it was also the way how they began the adventure with PHP development because it was so easy. Now we kind of have the, all the consequences of being that easy.<\/p>\n<p class=\"wp-block-paragraph\">[00:36:06] <strong>Nathan Wrigley:<\/strong> Yeah, in a sense, this is going to sound ridiculous, we should be glad that there\u2019s people talking about WordPress vulnerabilities, because it means the project is successful. And it also means that it\u2019s, there\u2019s an industry of WordPress security solutions, and there are people who take this very seriously and dedicate their lives to it. And you may not find that in some of these other ones, you know, some of the smaller CMSs and things like that.<\/p>\n<p class=\"wp-block-paragraph\">I think we\u2019ve probably hit about the sweet spot for the amount of time. But Maciek, I don\u2019t know if there was anything in that report that you have got lined up in your presentation that I never got to. If there was a particular thread that you wanted to pull. If there is, go for it.<\/p>\n<p class=\"wp-block-paragraph\">[00:36:46] <strong>Maciek Palmowski:<\/strong> No, I think we covered all the important things. And as you kind of said, this AI aspect, this will change so many things.<\/p>\n<p class=\"wp-block-paragraph\">[00:36:55] <strong>Nathan Wrigley:<\/strong> Yeah, we\u2019ll come back in two years and this conversation will be a very different thing.<\/p>\n<p class=\"wp-block-paragraph\">[00:36:57] <strong>Maciek Palmowski:<\/strong> Oh, I think even in few months which will be very interesting. Yeah, so this aspect, it\u2019s really very surprising. And I think that everyone who is right now kind of giving somewhere a talk about AI and security is in a very difficult spot because.<\/p>\n<p class=\"wp-block-paragraph\">[00:37:14] <strong>Nathan Wrigley:<\/strong> Yeah, your content is going to look stale quickly.<\/p>\n<p class=\"wp-block-paragraph\">[00:37:16] <strong>Maciek Palmowski:<\/strong> Yeah because you know it\u2019s like, but a week ago everything changed. Yeah, I have to rewrite everything.<\/p>\n<p class=\"wp-block-paragraph\">[00:37:20] <strong>Nathan Wrigley:<\/strong> Speaking of which, by the time that this goes out, hopefully you have managed to give out your presentation at WordCamp Europe. I will link to it and anything else that we\u2019ve mentioned today in the WP Tavern post. So go and check that out. But I will specifically link to the wordpress.tv version of your presentation, which no doubt will have been created by then. So Maciek, thank you for chatting to me today. Good luck. I hope presentation goes well.<\/p>\n<p class=\"wp-block-paragraph\">[00:37:43] <strong>Maciek Palmowski:<\/strong> Thank you. Thank you so much. Yes. I might need a bit because, you know, it\u2019s WordCamp Europe. It\u2019s a big conference.<\/p>\n<p class=\"wp-block-paragraph\">[00:37:49] <strong>Nathan Wrigley:<\/strong> It is, yeah. Good luck. I hope that you manage to stay calm.<\/p>\n<p class=\"wp-block-paragraph\">[00:37:52] <strong>Maciek Palmowski:<\/strong> Thank you.<\/p>\n<\/div>\n<\/details>\n<p class=\"wp-block-paragraph\">On the podcast today we have <a href=\"https:\/\/www.linkedin.com\/in\/maciekpalmowski\/\" target=\"_blank\" rel=\"noopener\">Maciek Palmowski<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Maciek is based in Poland and works at <a href=\"https:\/\/patchstack.com\/\" target=\"_blank\" rel=\"noopener\">Patchstack<\/a>, one of the companies in the WordPress ecosystem dedicated specifically to security. At Patchstack, Maciek collaborates with other security professionals on industry reports, bug bounty programs, and solutions for agencies, product owners, and hosting companies aiming to secure their client sites.<\/p>\n<p class=\"wp-block-paragraph\">I met up with Maciek at WordCamp Europe in Krak\u00f3w, and we discussed his presentation there. It examined the claims of \u201csecure hosting\u201d made by many WordPress hosting providers. He describes how Patchstack set out to test these claims with real-world penetration testing, using 30 known plugin vulnerabilities across multiple hosts, employing standardised methodologies, and validating their results independently. The findings are sobering. The majority of WordPress-specific attacks still get through, and there\u2019s a significant gap between the marketing hype and real protection.<\/p>\n<p class=\"wp-block-paragraph\">The conversation starts with Maciek\u2019s background and how his journey in the WordPress security space led to a focus on the promises made by hosts. From there, the discussion gets into the research approach: the selection of well-known vulnerabilities, consistent testing across different hosting environments, and the surprising result that even hosts with identical security tooling produced drastically different outcomes, showing it\u2019s not just about what tools you use, but how you use them.<\/p>\n<p class=\"wp-block-paragraph\">We talk about the \u201cSwiss cheese\u201d model of security, every layer will have holes, so you need multiple, overlapping defenses, and honest communication from hosts about their limitations. We also explored whether an industry-wide standard or badge for \u201csecure hosting\u201d is feasible or even desirable, given how easy it is for strong marketing claims to outpace reality.<\/p>\n<p class=\"wp-block-paragraph\">AI also enters the conversation, increasing both the speed and sophistication of attacks, and making patching and processes even more important, especially as the volume of vulnerabilities continues to rise and the time to exploitation drops.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019re interested in understanding what \u201csecure hosting\u201d really means, how to ask intelligent questions of providers, and the realities of WordPress security in 2026, this episode is for you.<\/p>\n<h2 class=\"wp-block-heading\">Useful links<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/patchstack.com\/\" target=\"_blank\" rel=\"noopener\">Patchstack<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/checkoutsummit.com\/\" target=\"_blank\" rel=\"noopener\">\u200aCheckout Summit<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/europe.wordcamp.org\/2026\/session\/testing-the-promise-does-secure-hosting-deliver\/\" target=\"_blank\" rel=\"noopener\">Testing the promise: does secure hosting deliver?<\/a> \u2013 Maciek\u2019s presentation at WordCamp Europe 2026. It includes the video of the presentation.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/patchstack.com\/whitepaper\/state-of-wordpress-security-in-2026\/\" target=\"_blank\" rel=\"noopener\">\u200aState of WordPress Security in 2026 Report<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/wpscan.com\/\" target=\"_blank\" rel=\"noopener\">WPScan<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Transcript [00:00:19] Nathan Wrigley: Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley. Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in this case, testing secure WordPress hosting, does the marketing match the reality? If you\u2019d like [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-11624","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"blog_post_layout_featured_media_urls":{"thumbnail":"","full":""},"categories_names":{"1":{"name":"Uncategorized","link":"https:\/\/4ksamachar.com\/?cat=1"}},"tags_names":[],"comments_number":"0","wpmagazine_modules_lite_featured_media_urls":{"thumbnail":"","cvmm-medium":"","cvmm-medium-plus":"","cvmm-portrait":"","cvmm-medium-square":"","cvmm-large":"","cvmm-small":"","full":""},"_links":{"self":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/posts\/11624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11624"}],"version-history":[{"count":0,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=\/wp\/v2\/posts\/11624\/revisions"}],"wp:attachment":[{"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/4ksamachar.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}