WPTaverm
Theo Marczak, guest on WP Taverm Jukebox

#45

Theo Marczak

WP Taverm Jukebox with Alex Harlan

Episode

#45 – Theo Marczak on Testing Whether Secure Hosting Matches the Marketing

Theo Marczak spent a year poking at WordPress hosts that sell “secure hosting.” Most WordPress-specific issues still slipped through. We unpack what the tests showed, and what buyers should ask next.

by Alex Harlan·July 29, 2026·with Theo Marczak

Listen

Search for WP Taverm in your podcast player, or copy the feed URL:

https://wptaverm.com/feed/podcast/

“Secure hosting” is a landing-page phrase. Theo Marczak treated it like a claim that could be tested. Over several months he ran WordPress-specific probes across a set of popular hosts: outdated PHP, world-writable directories, weak default users, and plugin supply-chain patterns that a generic WAF rarely sees.

The headline is uncomfortable. Marketing pages promised isolation and malware defense. In practice, most WordPress-shaped problems still reached the application. Network-layer protection is not the same as knowing how wp-config, cron, and the plugin installer behave.

Theo is careful not to turn this into a host-shaming list. The point is a buyer’s checklist: Who applies core updates? How fast do they patch a popular plugin CVE? Can you see the PHP version without opening a ticket? Is staging a copy or a prayer?

We close on what “good” looks like in 2026: automatic core and PHP upgrades with a rollback path, malware scanning that understands WordPress file layout, and an abuse desk that talks to other hosts. Security is a practice, not a badge.

Comments

  • Matthew Collins · August 2, 2026

    Appreciate the reminder that a WAF sticker is not a WordPress hardening policy. The plugin-update question is the one I’ll start asking.

Leave a Reply

Trending now